CVE-2004-0885 Affecting apache2 package, versions <2.0.52-2


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.18% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-APACHE2-391478
  • published3 Nov 2004
  • disclosed3 Nov 2004

Introduced: 3 Nov 2004

CVE-2004-0885  (opens in a new tab)

How to fix?

Upgrade Debian:10 apache2 to version 2.0.52-2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream apache2 package and not the apache2 package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

References

CVSS Scores

version 3.1