CNCVE编号:CNCVE-20020020 CVE编号: 安全级别:高 漏洞中文描述: Mod_SSL和Apache-SSL是Apache服务器上的SSL实现,用来为Apache web服务器提供加密支持。这个模块利用OpenSSL来完成SSL实现。版本低于2.8.7-1.3.23的Mod_SSL和Apache-SSL实现上以一种不安全方式使用OpenSSL函数,在某些条件下,可能导致缓冲区溢出,远程攻击者可能对服务器程序实施拒绝服务攻击或在主机上执行任意指令。Mod_SSL在实现SSL会话缓存机制时调用了OpenSSL的i3d_SSL_SESSION函数,OpenSSL要求在调用该函数时必须为其分配足够大小的内存以保存数据。但是由于Mod_SSL没有按照正确的方式进行调用,Mod_SSL在处理连续会话时可能导致一个静态缓冲区发生溢出。 漏洞英文描述: Mod_SSL and Apache-SSL are implementations of SSL (Secure Socket Layer) for the Apache webserver. A buffer overflow vulnerability exists in mod_ssl and Apache-SSL that may allow for attackers to execute arbitrary code. The overflow exists when the modules attempt to cache SSL sessions. Vulnerable versions of mod_ssl and Apache-SSL are incapable of handling large session representations. To exploit this vulnerability, the attacker must somehow increase the size of the data representing the session. This may be accomplished through the use of an extremely large client certificate. This is only possible if verification of client certificates is enabled, and if the certificate is verified by a CA trusted by the webserver. Though these requirements make this vulnerability theoretical, administrators are still urged to upgrade. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0313.html http://archives.neohapsis.com/archives/bugtraq/2002-02/0369.html http://www.apache-ssl.org/advisory-20020301.txt http://www.linuxsecurity.com/advisories/other_advisory-1923.html http://w 系统类型:其他 漏洞类型:其他