CVE-2004-0700

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2004
Last modified:
03/04/2025

Description

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mod_ssl:mod_ssl:2.3.11:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.6:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.7:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.8:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.9:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.4.10:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools