CVE-2002-0659
UnknownEPSS 36.04%
Last modified
CVE-2002-0659 is a vulnerability of currently unknown severity. The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.. EPSS estimates a 36.04% chance of exploitation in the next 30 days.
Description
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openssl | Openssl | 0.9.1c | — |
| Openssl | Openssl | 0.9.2b | — |
| Openssl | Openssl | 0.9.3 | — |
| Openssl | Openssl | 0.9.4 | — |
| Openssl | Openssl | 0.9.5 | — |
| Openssl | Openssl | 0.9.5a | — |
| Openssl | Openssl | 0.9.6 | — |
| Openssl | Openssl | 0.9.6a | — |
| Openssl | Openssl | 0.9.6b | — |
| Openssl | Openssl | 0.9.6c | — |
| Openssl | Openssl | 0.9.6d | — |
| Openssl | Openssl | 0.9.7 | Beta1 |
| Oracle | Application Server | All versions | — |
| Oracle | Application Server | 1.0.2 | — |
| Oracle | Application Server | 1.0.2.1s | — |
| Oracle | Application Server | 1.0.2.2 | — |
| Oracle | Corporate Time Outlook Connector | 3.1 | — |
| Oracle | Corporate Time Outlook Connector | 3.1.1 | — |
| Oracle | Corporate Time Outlook Connector | 3.1.2 | — |
| Oracle | Corporate Time Outlook Connector | 3.3 | — |
| Oracle | Http Server | 9.0.1 | — |
| Oracle | Http Server | 9.2.0 | — |
| Apple | Mac Os X | 10.0 | — |
| Apple | Mac Os X | 10.0.1 | — |
| Apple | Mac Os X | 10.0.2 | — |
| Apple | Mac Os X | 10.0.3 | — |
| Apple | Mac Os X | 10.0.4 | — |
| Apple | Mac Os X | 10.1 | — |
| Apple | Mac Os X | 10.1.1 | — |
| Apple | Mac Os X | 10.1.2 | — |
| Apple | Mac Os X | 10.1.3 | — |
| Apple | Mac Os X | 10.1.4 | — |
| Apple | Mac Os X | 10.1.5 | — |
References
- http://www.cert.org/advisories/CA-2002-23.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/748355US Government Resource
- http://www.cert.org/advisories/CA-2002-23.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/748355US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0659?
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
How severe is CVE-2002-0659?
Severity scoring for CVE-2002-0659 is pending analysis. The EPSS model estimates a 36.04% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0659?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2002-0659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
