CVE-2004-0009

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache-ssl:apache-ssl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-03-03 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2004-0009

Mitre link : CVE-2004-0009

CVE.ORG link : CVE-2004-0009


JSON object : View

Products Affected

apache-ssl

  • apache-ssl