CVE-2002-1568
published 2003-11-17CVE-2002-1568: OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.73%
84.4th percentile
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.6g-1 (bookworm) | openssl 0.9.6g-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.6g-1 | 0.9.6g-1 |
| openssl | openssl | >= 0 < 0.9.6g-1 | 0.9.6g-1 |
| openssl | openssl | >= 0 < 0.9.6g-1 | 0.9.6g-1 |
| openssl | openssl | >= 0 < 0.9.6g-1 | 0.9.6g-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3626-95rf-mfw3: OpenSSL 0
ghsa_unreviewed·2022-04-30
CVE-2002-1568 [MEDIUM] GHSA-3626-95rf-mfw3: OpenSSL 0
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
OSV
CVE-2002-1568: OpenSSL 0
osv·2003-11-17·CVSS 5.0
CVE-2002-1568 [MEDIUM] CVE-2002-1568: OpenSSL 0
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
Red Hat
security flaw
vendor_redhat·2003-10-02·CVSS 5.0
CVE-2002-1568 [MEDIUM] security flaw
security flaw
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
Debian
CVE-2002-1568: openssl - OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of...
vendor_debian·2002·CVSS 5.0
CVE-2002-1568 [MEDIUM] CVE-2002-1568: openssl - OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of...
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
Scope: local
bookworm: resolved (fixed in 0.9.6g-1)
bullseye: resolved (fixed in 0.9.6g-1)
forky: resolved (fixed in 0.9.6g-1)
sid: resolved (fixed in 0.9.6g-1)
trixie: resolved (fixed in 0.9.6g-1)
No detection rules found.
No public exploits indexed.
2003-11-17
Published