Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

BID:8134

Info

Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

Bugtraq ID: 8134
Class: Design Error
CVE: CVE-2003-0192
Remote: Yes
Local: No
Published: Jul 08 2003 12:00AM
Updated: Jul 11 2009 10:56PM
Credit: This issue was announced by the vendor.
Vulnerable: Sun Linux 5.0.7
Sun Cobalt RaQ XTR
Sun Cobalt RaQ 4
Sun Cobalt Qube 3
SCO Unixware 7.1.3
SCO Unixware 7.1.1
SCO Open UNIX 8.0
Apache Apache 2.0.46
+ Redhat Desktop 3.0
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux WS 3
+ Trustix Secure Linux 2.0
Apache Apache 2.0.45
- Apple Mac OS X 10.2.6
- Apple Mac OS X 10.2.5
- Apple Mac OS X 10.2.4
- Apple Mac OS X 10.2.3
- Apple Mac OS X 10.2.2
- Apple Mac OS X 10.2.1
- Apple Mac OS X 10.2
- Apple Mac OS X 10.1.5
- Apple Mac OS X 10.1.4
- Apple Mac OS X 10.1.3
- Apple Mac OS X 10.1.2
- Apple Mac OS X 10.1.1
- Apple Mac OS X 10.1
- Apple Mac OS X 10.1
- Apple Mac OS X 10.0.4
- Apple Mac OS X 10.0.3
- Apple Mac OS X 10.0.2
- Apple Mac OS X 10.0.1
- Apple Mac OS X 10.0
Apache Apache 2.0.44
Apache Apache 2.0.43
Apache Apache 2.0.42
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
Apache Apache 2.0.41
Apache Apache 2.0.40
+ Redhat Linux 9.0 i386
+ Redhat Linux 8.0
+ Terra Soft Solutions Yellow Dog Linux 3.0
Apache Apache 2.0.39
Apache Apache 2.0.38
Apache Apache 2.0.37
Apache Apache 2.0.36
Apache Apache 2.0.35
Apache Apache 2.0.32
Apache Apache 2.0.28
Apache Apache 2.0
Not Vulnerable: Apache Apache 2.0.47
+ Apple Mac OS X Server 10.3.5
+ Apple Mac OS X Server 10.3.4
+ Apple Mac OS X Server 10.3.3
+ Apple Mac OS X Server 10.3.2
+ Apple Mac OS X Server 10.3.1
+ Apple Mac OS X Server 10.3
+ Apple Mac OS X Server 10.2.8
+ Apple Mac OS X Server 10.2.7
+ Apple Mac OS X Server 10.2.6
+ Apple Mac OS X Server 10.2.5
+ Apple Mac OS X Server 10.2.4
+ Apple Mac OS X Server 10.2.3
+ Apple Mac OS X Server 10.2.2
+ Apple Mac OS X Server 10.2.1
+ Apple Mac OS X Server 10.2
+ Apple Mac OS X Server 10.1.5
+ Apple Mac OS X Server 10.1.4
+ Apple Mac OS X Server 10.1.3
+ Apple Mac OS X Server 10.1.2
+ Apple Mac OS X Server 10.1.1
+ Apple Mac OS X Server 10.1
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1

Discussion

Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

The Apache Software Foundation has reported an issue that may occur when the SSLCipherSuite directive is used to upgrade a cipher suite. Particular sequences of per-directory renegotiations may cause this condition to occur, resulting in a weaker cipher suite being used in place of the upgraded one.

Exploit / POC

Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

Solution:
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.

Trustix has released advisory 2003-0025 to address this issue.

Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details.

Red Hat has released advisory RHSA-2003:240-01 to address this issue.

HP has released advisory HPSBUX0309-278 to address this issue.

Red Hat has released an updated advisory RHSA-2003:243-01 to address this issue.

Red Hat has released an updated advisory RHSA-2003:244-01 to address this issue.

SCO has released security advisory CSSA-2003-SCO.28 with fixes to address this issue in OpenServer 5.0.5 through 5.0.7.

Sun has released fixes for Sun Linux 5.0.7 and RaQ systems.

This issue is addressed with the release of Apache 2.0.47. Users are advised to upgrade.

SCO has released security advisory SCOSA-2004.6 with fixes to address this issue in UnixWare 7.1.3, Open UNIX 8.0.0 and UnixWare 7.1.1. Please see the advisory for more information.


Sun Cobalt Qube 3

Sun Cobalt RaQ 4

Sun Cobalt RaQ XTR

Apache Apache 2.0

Apache Apache 2.0.28

Apache Apache 2.0.32

Apache Apache 2.0.35

Apache Apache 2.0.36

Apache Apache 2.0.37

Apache Apache 2.0.38

Apache Apache 2.0.39

Apache Apache 2.0.40

Apache Apache 2.0.41

Apache Apache 2.0.42

Apache Apache 2.0.43

Apache Apache 2.0.44

Apache Apache 2.0.45

Apache Apache 2.0.46

Sun Linux 5.0.7

SCO Unixware 7.1.1

SCO Unixware 7.1.3

SCO Open UNIX 8.0

References

Apache Web Server SSLCipherSuite Weak CipherSuite Renegotiation Weakness

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report