CVE-2002-0655Openssl vulnerability

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 3

Description

OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianopenssl/openssl< 0.9.6e-1+3
NVDopenssl/openssl12 versions+11
NVDapple/mac_os_x11 versions+10
NVDoracle/http_server9.0.1, 9.2.0+1
NVDoracle/application_server1.0.2, 1.0.2.1s, 1.0.2.2+2

🔴Vulnerability Details

3
GHSA
GHSA-qqh8-wx7x-qgh9: OpenSSL 02022-05-03
OSV
CVE-2002-0655: OpenSSL 02002-08-12
CVEList
CVE-2002-0655: OpenSSL 02002-07-31

📋Vendor Advisories

2
Red Hat
security flaw2002-07-30
Debian
CVE-2002-0655: openssl - OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handl...2002

💬Community

1
Bugzilla
CVE-2002-0655 security flaw2018-08-16
CVE-2002-0655 — Openssl vulnerability | cvebase