Upstream information
Description
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 7.5 |
Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
SUSE Security Advisories:
- SUSE-SA:2004:040, published Monday, Nov 15th 2004 18:00 MEST
- SUSE-SA:2004:041, published Wednesday, Nov 17th 2004 15:00 MET
- SUSE-SR:2004:001, published Wednesday, Nov 24th 2004 12:00 MEST
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 00:59:21 2013CVE page last modified: Fri Dec 8 16:10:15 2023