Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0659Openssl vulnerability

8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
7.9%
top 7.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 12
Latest updateMay 3

Description

The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

Debianopenssl/openssl< 0.9.6e-1+3
NVDopenssl/openssl12 versions+11
NVDapple/mac_os_x11 versions+10
NVDoracle/http_server9.0.1, 9.2.0+1
NVDoracle/application_server1.0.2, 1.0.2.1s, 1.0.2.2+2

🔴Vulnerability Details

3
GHSA
GHSA-3x2f-268g-8hg7: The ASN1 library in OpenSSL 02022-05-03
OSV
CVE-2002-0659: The ASN1 library in OpenSSL 02002-08-12
CVEList
CVE-2002-0659: The ASN1 library in OpenSSL 02002-07-31

💥Exploits & PoCs

1
Exploit-DB
OpenSSL - ASN.1 Parsing2003-10-09

📋Vendor Advisories

2
Red Hat
security flaw2002-07-30
Debian
CVE-2002-0659: openssl - The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, all...2002

💬Community

1
Bugzilla
CVE-2002-0659 security flaw2018-08-16
CVE-2002-0659 — Openssl vulnerability | cvebase