CVE-2002-0082: Buffer Overflow
The dbm and shm session cache code in modssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2dSSLSESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0082?
CVE-2002-0082 is considered to have a critical severity due to its potential to allow remote execution of arbitrary code.
How do I fix CVE-2002-0082?
To fix CVE-2002-0082, upgrade to a patched version of mod_ssl after 2.8.7 or Apache-SSL after 1.3.22+1.46.
What software is affected by CVE-2002-0082?
CVE-2002-0082 affects multiple versions of mod_ssl and Apache-SSL, specifically versions before 2.8.7-1.3.23 for mod_ssl and 1.3.22+1.46 for Apache-SSL.
What type of attack can exploit CVE-2002-0082?
CVE-2002-0082 can be exploited through a buffer overflow attack using a large client certificate that is signed.
Is CVE-2002-0082 still relevant today?
While CVE-2002-0082 was reported over two decades ago, it remains relevant for maintaining secure configurations on legacy systems that still use the vulnerable software.