PT-2003-1300 · Openssl · Openssl

Published

2002-08-08

·

Updated

2016-10-18

·

CVE-2002-1568

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL version 0.9.6e
Description The issue allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion. This is demonstrated using SSLv2 CLIENT MASTER KEY messages, which are not properly handled in s2 srvr.c.
Recommendations For OpenSSL version 0.9.6e, consider updating to a newer version that properly handles buffer overflow attacks with less severe mechanisms than assertions to prevent denial of service crashes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1568

Affected Products

Openssl