CVE-2005-3357

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 06 Jan 2006, 23:00
Last modified:07 Aug 2024, 23:10

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
5.4 MEDIUM
v2.0 (nvd)
EPSS Score
43.46% HIGH
43% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Jan 2006, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 23:10
Last Modified
Vulnerability information updated

Description

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.

CVSS Metrics

  • v2.0MEDIUMScore: 5.4AV:N/AC:H/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 43.46% Percentile: 98%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • UnknownHTTP Server

    2.0 | 2.0.9 | 2.0.28 | 2.0.28:beta | 2.0.32 | 2.0.35 | 2.0.36 | 2.0.37 | 2.0.38 | 2.0.39 | 2.0.40 | 2.0.41 | 2.0.42 | 2.0.43 | 2.0.44 | 2.0.45 | 2.0.46 | 2.0.47 | 2.0.48 | 2.0.49 | 2.0.50 | 2.0.51 | 2.0.52 | 2.0.53 | 2.0.54 | 2.0.55

References (66)