Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-200407-18 Moderate: mod_ssl Code Execution Risk

gentoo
Calendar Grey July 22, 2004
Scroller Gentoo
Debian Security Advisory DSA-2023-22 points to a significant vulnerability in OpenSSL that could allow unauthorized access due to improper input validation.
A bug in mod_ssl may allow a remote attacker to execute arbitrary code when Apache is configured to use mod_ssl and mod_proxy.

Summary

Gentoo Linux Security Advisory GLSA 200407-18 https://security.gentoo.org/ Severity: Normal Title: mod_ssl: Format string vulnerability Date: July 22, 2004 Bugs: #57379 ID: 200407-18

Synopsis ======= A bug in mod_ssl may allow a remote attacker to execute arbitrary code when Apache is configured to use mod_ssl and mod_proxy.
Background ========= mod_ssl provides Secure Sockets Layer encryption and authentication to Apache 1.3.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-www/mod_ssl <= 2.8.18 >= 2.8.19
========== A bug in ssl_engine_ext.c makes mod_ssl vulnerable to a ssl_log() related format string vulnerability in the mod_proxy hook functio...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround