VDB
CVE-2002-0656
CVE-2002-0656
PUBLISHED
CVSS 7.5 HIGH
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
EPSS 89.82% · 99.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
89.82%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openssl | openssl | 0.9.1c, 0.9.2b, 0.9.3 |
| apple | mac_os_x | 10.0.3, 10.1.5, 10.1.4 |
| oracle | http_server | 9.2.0, 9.0.1 |
| oracle | application_server | 1.0.2.1s, 1.0.2, 1.0.2.2 |
| n/a | n/a | n/a |
| oracle | corporate_time_outlook_connector | 3.1, 3.1.2, 3.1.1 |
Timeline
- Jul 31, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- May 3, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- 5363 vdb
- 5362 vdb
- VU#258555 third-party-advisory
- openssl-ssl2-masterkey-bo(9714) vdb
- CSSA-2002-033.1 vendor-advisory
- VU#102795 third-party-advisory
- openssl-ssl3-sessionid-bo(9716) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2002-0656 advisory
- http://www.cert.org/advisories/CA-2002-23.html url
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txt technical
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000513 technical
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-046.php technical
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.asc technical