CVE-2004-0009
Publication date 3 March 2004
Last updated 17 July 2025
Ubuntu priority
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the “one-line DN” of the target user.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache | 7.04 feisty |
Fixed 1.3.34-4ubuntu1
|
6.10 edgy |
Fixed 1.3.34-4ubuntu1
|
|
6.06 LTS dapper |
Fixed 1.3.34-2ubuntu0.1
|