Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
CVSS v2.0 Score
7.5
/ 10.0
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
Information
- Published
- 12 août 2002
- Updated
- 16 avr. 2026
- Status
- Modified
- Source
- cve@mitre.org
Affected products
openssl opensslAll OpenSSL CVEs →
Versions : 0.9.1c, 0.9.2b, 0.9.3, 0.9.4, 0.9.5
oracle application server
Versions : 1.0.2, 1.0.2.1s, 1.0.2.2
oracle corporate time outlook connector
Versions : 3.1, 3.1.1, 3.1.2, 3.3
oracle http serverAll Apache HTTP Server CVEs →
Versions : 9.0.1, 9.2.0
apple mac os x
Versions : 10.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4
Weaknesses (CWE)
NVD-CWE-Other
References (24)
- http://www.cert.org/advisories/CA-2002-23.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/102795US Government Resource
- http://www.kb.cert.org/vuls/id/258555US Government Resource
- + 9 more references on NVD
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.