Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and previous versions, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
modssl mod ssl |