Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 2.0.35 | 2.0.50 |
| debian / debian_linux | 3.0 | 3.0.x |
| redhat / enterprise_linux_server | 2.0 | 2.0.x |
| redhat / enterprise_linux_workstation | 2.0 | 2.0.x |