FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Apache-SSL optional client certificate vulnerability

Affected packages
apache+ssl < 1.3.29.1.53

Details

VuXML ID 7557a2b1-5d63-11d8-80e3-0020ed76ef5a
Discovery 2004-02-06
Entry 2004-02-10

From the Apache-SSL security advisory:

If configured with SSLVerifyClient set to 1 or 3 (client certificates optional) and SSLFakeBasicAuth, Apache-SSL 1.3.28+1.52 and all earlier versions would permit a client to use real basic authentication to forge a client certificate.

All the attacker needed is the "one-line DN" of a valid user, as used by faked basic auth in Apache-SSL, and the fixed password ("password" by default).

References

URL http://www.apache-ssl.org/advisory-20040206.txt