CVE-2002-0656
UnknownEPSS 89.82%
Last modified
CVE-2002-0656 is a vulnerability of currently unknown severity. Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.. EPSS estimates a 89.82% chance of exploitation in the next 30 days.
Description
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openssl | Openssl | 0.9.1c | — |
| Openssl | Openssl | 0.9.2b | — |
| Openssl | Openssl | 0.9.3 | — |
| Openssl | Openssl | 0.9.4 | — |
| Openssl | Openssl | 0.9.5 | — |
| Openssl | Openssl | 0.9.5a | — |
| Openssl | Openssl | 0.9.6 | — |
| Openssl | Openssl | 0.9.6a | — |
| Openssl | Openssl | 0.9.6b | — |
| Openssl | Openssl | 0.9.6c | — |
| Openssl | Openssl | 0.9.6d | — |
| Openssl | Openssl | 0.9.7 | Beta1 |
| Oracle | Application Server | All versions | — |
| Oracle | Application Server | 1.0.2 | — |
| Oracle | Application Server | 1.0.2.1s | — |
| Oracle | Application Server | 1.0.2.2 | — |
| Oracle | Corporate Time Outlook Connector | 3.1 | — |
| Oracle | Corporate Time Outlook Connector | 3.1.1 | — |
| Oracle | Corporate Time Outlook Connector | 3.1.2 | — |
| Oracle | Corporate Time Outlook Connector | 3.3 | — |
| Oracle | Http Server | 9.0.1 | — |
| Oracle | Http Server | 9.2.0 | — |
| Apple | Mac Os X | 10.0 | — |
| Apple | Mac Os X | 10.0.1 | — |
| Apple | Mac Os X | 10.0.2 | — |
| Apple | Mac Os X | 10.0.3 | — |
| Apple | Mac Os X | 10.0.4 | — |
| Apple | Mac Os X | 10.1 | — |
| Apple | Mac Os X | 10.1.1 | — |
| Apple | Mac Os X | 10.1.2 | — |
| Apple | Mac Os X | 10.1.3 | — |
| Apple | Mac Os X | 10.1.4 | — |
| Apple | Mac Os X | 10.1.5 | — |
References
- http://www.cert.org/advisories/CA-2002-23.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/102795US Government Resource
- http://www.kb.cert.org/vuls/id/258555US Government Resource
- http://www.cert.org/advisories/CA-2002-23.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/102795US Government Resource
- http://www.kb.cert.org/vuls/id/258555US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0656?
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
How severe is CVE-2002-0656?
Severity scoring for CVE-2002-0656 is pending analysis. The EPSS model estimates a 89.82% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0656?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2002-0656?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
