CVE-2005-3357
EPSS 24.3%
描述
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
如何修補 CVE-2005-3357
要修補 CVE-2005-3357,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.0.55-4 或更新版本
CVE-2005-3357 正在被利用嗎?
中等 — EPSS 為 24.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.0.55-4