CVE-2002-1568
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
OpenSSL 0.96e usa aserciones cuando detecta ataques de desbordamineto de búfer en vez de mencanismos menos severos,lo que permite a atacantes remotos causar una denegación de servicio (caída) mediante ciertos mensajes que hacen que OpenSSL aborte de una aserción fallida, como se ha demostrado usando mensajes SSLv2 CLIENT_MASTER_KEY, que no son manejados adecuadamente en s2_srvr.c
CVSS Scores
SSVC
- Decision:-
Timeline
- 2003-10-06 CVE Reserved
- 2003-10-08 CVE Published
- 2024-08-05 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=106511018214983 | Mailing List | |
http://www.ebitech.sk/patrik/SA/SA-20031002.txt | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://cvs.openssl.org/chngview?cn=7659 | 2016-10-18 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2002-1568 | 2002-07-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1616924 | 2002-07-30 |