CVE-2002-0656
published 2002-08-12CVE-2002-0656: Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
89.82%
99.8th percentile
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| debian | openssl | < openssl 0.9.6e-1 (bookworm) | openssl 0.9.6e-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.6e-1 | 0.9.6e-1 |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
AAAA...\x00\x00\x00\x00...\x01\x00\x00\x00...\x11\x00\x00\x00fdfd bkbk\x10\x00\x00\x00\x10\x00\x00\x00
bytes↗
AAAA...\x70\x00\x00\x00
- →Exploit targets the KEY_ARG buffer overflow in SSL2 CLIENT_MASTER_KEY message; detect oversized KEY_ARG fields (>8 bytes normal) in SSLv2 handshake traffic on port 443 or other SSL ports. ↗
- →Exploit uses an info-leak via SERVER_FINISHED message by overwriting session_id_length to 0x70 (112 bytes) to leak heap addresses; detect anomalously large session_id_length values in SSLv2 SERVER_FINISHED messages. ↗
- →Exploit opens a large number of simultaneous SSL connections (default 30–50) to the target before sending shellcode; detect rapid bursts of SSLv2 connection attempts from a single source IP. ↗
- →The exploit overwrites the GOT free() entry via heap unlink; the malloc chunk overwrite pattern uses the sentinel bytes \x11\x00\x00\x00 (chunk size) and the ASCII strings 'fdfd'/'bkbk' as fd/bk pointers — these are detectable in raw SSL payload bytes. ↗
- →Vulnerable server banner pattern to identify unpatched targets: Apache with mod_ssl/2.8.x and OpenSSL/0.9.6b or earlier in HTTP Server response header. ↗
- →CVE affects SSLv2 (large client master key) and SSLv3 (large session ID); block or alert on SSLv2 handshakes entirely as a detection/prevention measure, since SSLv2 is deprecated and its use is anomalous. ↗
- ·The exploit only supports Linux/x86 targets; other platforms (big-endian, non-x86) are not exploitable by this specific tool, though the underlying vulnerability may still be present. ↗
- ·The exploit targets Apache (running as 'nobody') by default; against other servers running as root, the resulting shell would have root privileges. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2002-07-30·CVSS 7.5
CVE-2002-0656 [HIGH] security flaw
security flaw
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Debian
CVE-2002-0656: openssl - Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, all...
vendor_debian·2002·CVSS 7.5
CVE-2002-0656 [HIGH] CVE-2002-0656: openssl - Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, all...
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Scope: local
bookworm: resolved (fixed in 0.9.6e-1)
bullseye: resolved (fixed in 0.9.6e-1)
forky: resolved (fixed in 0.9.6e-1)
sid: resolved (fixed in 0.9.6e-1)
trixie: resolved (fixed in 0.9.6e-1)
GHSA
GHSA-9jw8-9j6r-p392: Buffer overflows in OpenSSL 0
ghsa_unreviewed·2022-05-03
CVE-2002-0656 [HIGH] GHSA-9jw8-9j6r-p392: Buffer overflows in OpenSSL 0
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
OSV
CVE-2002-0656: Buffer overflows in OpenSSL 0
osv·2002-08-12·CVSS 7.5
CVE-2002-0656 [HIGH] CVE-2002-0656: Buffer overflows in OpenSSL 0
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Suricata
GPL FTP USER overflow attempt
suricata·2010-09-23
CVE-1999-1510 GPL FTP USER overflow attempt
GPL FTP USER overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP USER overflow attempt"; flow:established,to_server,no_stream; content:"USER|20|"; nocase; isdataat:100,relative; pcre:"/^USER\x20[^\x00\x20\x0a\x0d]{100}/smi"; reference:bugtraq,10078; reference:bugtraq,1227; reference:bugtraq,1504; reference:bugtraq,1690; reference:bugtraq,4638; reference:bugtraq,7307; reference:bugtraq,8376; reference:cve,1999-1510; reference:cve,1999-1514; reference:cve,1999-1519; reference:cve,1999-1539; reference:cve,2000-0479; reference:cve,2000-0656; reference:cve,2000-0761; reference:cve,2000-0943; reference:cve,2000-1035; reference:cve,2000-1194; reference:cve,2001-0256; reference:cve,2001-0794; reference:cve,2001-0826; reference:cve,2002-0126; reference:cve,2002-1522;
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txtftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.1.txtftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000513http://www.cert.org/advisories/CA-2002-23.htmlhttp://www.iss.net/security_center/static/9714.phphttp://www.iss.net/security_center/static/9716.phphttp://www.kb.cert.org/vuls/id/102795http://www.kb.cert.org/vuls/id/258555http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-046.phphttp://www.securityfocus.com/bid/5362http://www.securityfocus.com/bid/5363ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txtftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.1.txtftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000513http://www.cert.org/advisories/CA-2002-23.htmlhttp://www.iss.net/security_center/static/9714.phphttp://www.iss.net/security_center/static/9716.phphttp://www.kb.cert.org/vuls/id/102795http://www.kb.cert.org/vuls/id/258555http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-046.phphttp://www.securityfocus.com/bid/5362http://www.securityfocus.com/bid/5363
2002-08-12
Published