CVE-2004-0885

Publication date 3 November 2004

Last updated 17 July 2025


Ubuntu priority

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the “SSLCipherSuite” directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
apache2 7.04 feisty
Fixed 2.2.3-3.2ubuntu0.1
6.10 edgy
Fixed 2.0.55-4ubuntu4.1
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.2
libapache-mod-ssl 7.04 feisty
Fixed 2.8.25-1
6.10 edgy
Fixed 2.8.25-1
6.06 LTS dapper
Fixed 2.8.25-1