ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10416
https://lists.opensuse.org/opensuse-security-announce/2006-09/msg00016.html
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167195
http://www.vupen.com/english/advisories/2006/4207
http://www.vupen.com/english/advisories/2006/0789
http://www.vupen.com/english/advisories/2005/2659
http://www.vupen.com/english/advisories/2005/1625
http://www.ubuntu.com/usn/usn-177-1
http://www.securityfocus.com/bid/14721
http://www.redhat.com/support/errata/RHSA-2005-816.html
http://www.redhat.com/support/errata/RHSA-2005-773.html
http://www.redhat.com/support/errata/RHSA-2005-608.html
http://www.kb.cert.org/vuls/id/744929
http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml
http://www.debian.org/security/2005/dsa-807
http://www.debian.org/security/2005/dsa-805
http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
http://secunia.com/advisories/22523
http://secunia.com/advisories/21848
http://secunia.com/advisories/19073
http://secunia.com/advisories/19072
http://secunia.com/advisories/17813
http://secunia.com/advisories/17311
http://secunia.com/advisories/17288
http://secunia.com/advisories/17088
http://secunia.com/advisories/16956
http://secunia.com/advisories/16864
http://secunia.com/advisories/16789
http://secunia.com/advisories/16771
http://secunia.com/advisories/16769
http://secunia.com/advisories/16754
http://secunia.com/advisories/16753
http://secunia.com/advisories/16748
http://secunia.com/advisories/16746
http://secunia.com/advisories/16743
http://secunia.com/advisories/16714
http://secunia.com/advisories/16705
http://secunia.com/advisories/16700
http://people.apache.org/~jorton/CAN-2005-2700.diff
http://marc.info/?l=bugtraq&m=112870296926652&w=2