Back
CVE-2004-0700
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
Published: Jul 27, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (44)
| Vendor | Product | Version |
|---|---|---|
| mod_ssl | mod_ssl | 2.3.11 |
| mod_ssl | mod_ssl | 2.4.0 |
| mod_ssl | mod_ssl | 2.4.1 |
| mod_ssl | mod_ssl | 2.4.2 |
| mod_ssl | mod_ssl | 2.4.3 |
| mod_ssl | mod_ssl | 2.4.4 |
| mod_ssl | mod_ssl | 2.4.5 |
| mod_ssl | mod_ssl | 2.4.6 |
| mod_ssl | mod_ssl | 2.4.7 |
| mod_ssl | mod_ssl | 2.4.8 |
| mod_ssl | mod_ssl | 2.4.9 |
| mod_ssl | mod_ssl | 2.4.10 |
| mod_ssl | mod_ssl | 2.5.0 |
| mod_ssl | mod_ssl | 2.5.1 |
| mod_ssl | mod_ssl | 2.6.0 |
| mod_ssl | mod_ssl | 2.6.1 |
| mod_ssl | mod_ssl | 2.6.2 |
| mod_ssl | mod_ssl | 2.6.3 |
| mod_ssl | mod_ssl | 2.6.4 |
| mod_ssl | mod_ssl | 2.6.5 |
…and 24 more
GitHub Security Advisory GHSA-mm6m-9rf6-5j2q
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in...
References (30)
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000857
- http://marc.info/?l=apache-modssl&m=109001100906749&w=2
- http://marc.info/?l=bugtraq&m=109005001205991&w=2
- http://packetstormsecurity.org/0407-advisories/modsslFormat.txt
- http://virulent.siyahsapka.org/
- http://www.debian.org/security/2004/dsa-532
- http://www.kb.cert.org/vuls/id/303448 Third Party Advisory, US Government Resource
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:075
- http://www.osvdb.org/7929
- http://www.redhat.com/support/errata/RHSA-2004-405.html
- http://www.redhat.com/support/errata/RHSA-2004-408.html
- http://www.securityfocus.com/bid/10736
- http://www.ubuntu.com/usn/usn-177-1
- https://bugzilla.fedora.us/show_bug.cgi?id=1888
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16705
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
5.80%
Top 8% most likely to be exploited
Threat Score
31.7 / 100
Data Sources
NVD
EPSS
GitHub