CVE-2005-1268

Publication date 5 August 2005

Last updated 17 July 2025


Ubuntu priority

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
apache2 7.04 feisty
Fixed 2.2.3-3.2ubuntu0.1
6.10 edgy
Fixed 2.0.55-4ubuntu4.1
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.2

References

Related Ubuntu Security Notices (USN)

    • USN-160-1
    • Apache 2 vulnerabilities
    • 4 August 2005

Other references