ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 2.0.35 | 2.0.55 |
| debian / debian_linux | 3.1 | 3.1.x |
| debian / debian_linux | 3.0 | 3.0.x |
| canonical / ubuntu_linux | 4.10 | 4.10.x |
| canonical / ubuntu_linux | 5.04 | 5.04.x |