> -----Original Message-----
> From: Udo Schweigert [mailto:[EMAIL PROTECTED]
> Sent: Donnerstag, 27. Mai 2004 17:03
> To: [EMAIL PROTECTED]
> Subject: Re: [ANNOUNCE] mod_ssl 2.8.18
> 
> 
> On Thu, May 27, 2004 at 15:21:37 +0200, Ralf S. Engelschall wrote:
> >   Changes with mod_ssl 2.8.18 (11-May-2004 to 27-May-2004)
> > 
> >    *) Fix buffer overflow in "SSLOptions +FakeBasicAuth" 
> implementation
> >       if the Subject-DN in the client certificate exceeds 
> 6KB in length.
> >       (CVE CAN-2004-0488).
> > 
> 
> Is that also an issue in apache-2.x? (I wasn't able to find 
> that CVE, so I
> ask here ;-)

The problem was originally identified on apache2 (see
http://www.securityfocus.com/bid/10355/) and it has already been patched
there. 

Incidentally, AFAIK there is no vulnerability unless you are using
"SSLOptions FakeBasicAuth". It's a fairly specialised option so my
feeling is that this doesn't urgently affect a whole lot of people... Of
course, you should still upgrade just in case some time in the future
you do switch that option on.

Rgds,
Owen Boyle
Disclaimer: Any disclaimer attached to this message may be ignored. 

> 
> Best regards
> 
> Udo
> --
> Udo Schweigert, Siemens AG   | Voice      : +49 89 636 42170
> CT IC CERT, Siemens CERT     | Fax        : +49 89 636 41166
> D-81730 München / Germany    | email      : [EMAIL PROTECTED]
> ______________________________________________________________________
> Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
> User Support Mailing List                      [EMAIL PROTECTED]
> Automated List Manager                            [EMAIL PROTECTED]
> 
Diese E-mail ist eine private und persönliche Kommunikation. Sie hat
keinen Bezug zur Börsen- bzw. Geschäftstätigkeit der SWX Gruppe. This
e-mail is of a private and personal nature. It is not related to the
exchange or business activities of the SWX Group. Le présent e-mail est
un message privé et personnel, sans rapport avec l'activité boursière du
Groupe SWX.

This message is for the named person's use only. It may contain
confidential, proprietary or legally privileged information. No
confidentiality or privilege is waived or lost by any mistransmission.
If you receive this message in error, please notify the sender urgently
and then immediately delete the message and any copies of it from your
system. Please also immediately destroy any hardcopies of the message.
You must not, directly or indirectly, use, disclose, distribute, print,
or copy any part of this message if you are not the intended recipient.
The sender's company reserves the right to monitor all e-mail
communications through their networks. Any views expressed in this
message are those of the individual sender, except where the message
states otherwise and the sender is authorised to state them to be the
views of the sender's company. 


______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to