SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#744929

mod_ssl fails to properly enforce client certificates authentication

Overview

mod_ssl, the Apache web server module for Secure Socket Layer (SSL) communications, may not properly authenticate client certificates.

I. Description

mod_ssl provides Secure Socket Layer (SSL) communications for the Apache web server. SSL is designed to provide the ability to encrypt and authenticate TCP connections. Apache, using mod_ssl, can be configured to use SSL to authenticate web users using client certificates.

The requirement for client certificates is not enforced if a web server configuration specifies client authentication as optional ("SSLVerifyClient optional") in the global virtual host configuration, but specifies client certificates as required in some location's context ("SSLVerifyClient require").

II. Impact

An attacker may access web documents in a restricted section of a web site without providing a valid client certificate.

III. Solution

Upgrade to mod_ssl 2.8.24 or later, or apply a patch as specified by your vendor.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apache-SSLUnknown9-Sep-2005
Apache HTTP Server ProjectVulnerable18-Oct-2005
Apple Computer, Inc.Unknown6-Dec-2005
Avaya, Inc.Vulnerable3-Oct-2005
Cray, Inc.Unknown7-Sep-2005
Debian LinuxVulnerable12-Sep-2005
EMC, Inc. (formerly Data General Corporation)Unknown7-Sep-2005
Engarde Secure LinuxUnknown7-Sep-2005
F5 Networks, Inc.Vulnerable8-Sep-2005
Fedora ProjectVulnerable9-Sep-2005
FreeBSD, Inc.Unknown7-Sep-2005
Fujitsu LimitedUnknown7-Sep-2005
Gentoo LinuxVulnerable23-Sep-2005
Hewlett-Packard CompanyUnknown7-Oct-2005
HitachiUnknown23-Sep-2005
IBM CorporationUnknown7-Sep-2005
Immunix Communications, Inc.Unknown7-Sep-2005
Ingrian Networks, Inc. Unknown7-Sep-2005
Juniper Networks, Inc.Not Vulnerable9-Sep-2005
Mandriva, Inc.Vulnerable3-Oct-2005
Mandriva, Inc.Vulnerable9-Sep-2005
Microsoft CorporationNot Vulnerable9-Sep-2005
mod_sslVulnerable9-Sep-2005
MontaVista Software, Inc.Unknown7-Sep-2005
NEC CorporationUnknown7-Sep-2005
NetBSDUnknown7-Sep-2005
NokiaUnknown12-Sep-2005
Novell, Inc. Unknown7-Sep-2005
OpenBSDUnknown7-Sep-2005
OpenPKGVulnerable7-Sep-2005
Openwall GNU/*/LinuxNot Vulnerable8-Sep-2005
Oracle CorporationVulnerable18-Oct-2006
QNX, Software Systems, Inc.Unknown7-Sep-2005
Red Hat, Inc.Vulnerable28-Dec-2005
Silicon Graphics, Inc.Unknown7-Sep-2005
Slackware Linux Inc.Vulnerable9-Sep-2005
Sony CorporationUnknown7-Sep-2005
Sun Microsystems, Inc.Unknown7-Sep-2005
SUSE LinuxVulnerable16-Sep-2005
The SCO Group (SCO UnixWare)Unknown7-Sep-2005
Trustix Secure LinuxVulnerable9-Sep-2005
TurbolinuxUnknown7-Sep-2005
UbuntuVulnerable8-Sep-2005
UnisysUnknown7-Sep-2005
Wind River Systems, Inc.Unknown7-Sep-2005

References


http://svn.apache.org/viewcvs?rev=264800&view=rev
http://www.mail-archive.com/modssl-users@modssl.org/msg17148.html
http://marc.theaimsgroup.com/?l=apache-modssl&m=112569517603897&w=2
http://secunia.com/advisories/16700/
http://www.osvdb.org/19188
http://www.openpkg.org/security/OpenPKG-SA-2005.017-modssl.html
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167195
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167194
http://rhn.redhat.com/errata/RHSA-2005-608.html
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.458879

Credit

Reported by Joe Orton of Red Hat.

This document was written by Hal Burch.

Other Information

Date Public:2005-08-31
Date First Published:2005-09-09
Date Last Updated:2006-10-18
CERT Advisory: 
CVE-ID(s):CVE-2005-2700
NVD-ID(s):CVE-2005-2700
US-CERT Technical Alerts: 
Metric:1.45
Document Revision:69

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader