Title: Apache HTTP Server mod_ssl SSLVerifyClient Per-location Context Restriction Bypass
Info
Disclosure
Sep 02, 2005
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
mod_ssl contains a flaw that may allow a malicious user to bypass certain security restrictions. The issue is due to an error in enforcing client-based certificate authentication ("SSLVerifyClient require") in per-location context, if "SSLVerifyClient optional" was configured in the global virtual host configuration. It is possible that the flaw may allow an attacker to bypass client-based certificate authentication, resulting in a loss of confidentiality or integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version 2.8.24 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.