Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache-SSL ExpandCert 身份认证和权限验证漏洞
Vulnerability Description
Apache-SSL apache_1.3.41+ssl_1.59之前的版本中的ExpandCert函数,没有正确的处理客户信任凭证中的标识符中的(1) '/'和(2)'='字符,这可能使得运程攻击者可以借助一个特制的DN,绕过身份验证。该DN会触发对环境变量的重写。
CVSS Information
N/A
Vulnerability Type
N/A