Buffer Overflow Vulnerability in OpenSSL Affecting Multiple Platforms
CVE-2002-0656

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
12 August 2002

What is CVE-2002-0656?

Remote attackers can exploit a buffer overflow vulnerability in OpenSSL versions 0.9.6d and earlier, and 0.9.7-beta2 and earlier. This vulnerability enables them to execute arbitrary code by supplying a large client master key in SSL2 or a large session ID in SSL3, which can compromise the integrity and availability of the systems using these versions of OpenSSL.

References

EPSS Score

90% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.