CVE-2002-0656: Buffer Overflow
Published Jul 31, 2002
·Updated
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
Affected Software
34 affected components
OpenSSL OpenSSL=0.9.1c
OpenSSL OpenSSL=0.9.2b
OpenSSL OpenSSL=0.9.3
OpenSSL OpenSSL=0.9.4
OpenSSL OpenSSL=0.9.5
OpenSSL OpenSSL=0.9.5a
OpenSSL OpenSSL=0.9.6
OpenSSL OpenSSL=0.9.6a
OpenSSL OpenSSL=0.9.6b
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.7-beta1
OpenSSL OpenSSL=0.9.7-beta2
Oracle Application Server
Oracle Application Server=1.0.2
Oracle Application Server=1.0.2.1s
Oracle Application Server=1.0.2.2
Oracle Corporate Time Outlook Connector=3.1
Oracle Corporate Time Outlook Connector=3.1.1
Oracle Corporate Time Outlook Connector=3.1.2
Oracle Corporate Time Outlook Connector=3.3
Oracle HTTP Server=9.0.1
Oracle HTTP Server=9.2.0
Apple iOS and macOS=10.0
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1
Apple iOS and macOS=10.1.1
Apple iOS and macOS=10.1.2
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.1.5
Event History
Jul 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0656?
CVE-2002-0656 is considered to have a high severity due to potential remote code execution vulnerabilities.
2
How do I fix CVE-2002-0656?
To fix CVE-2002-0656, upgrade OpenSSL to version 0.9.7 or later, which contains patches for this vulnerability.
3
Which versions of OpenSSL are affected by CVE-2002-0656?
CVE-2002-0656 affects OpenSSL versions 0.9.6d and earlier, and 0.9.7-beta2 and earlier.
4
What types of attacks are possible with CVE-2002-0656?
CVE-2002-0656 allows remote attackers to execute arbitrary code through buffer overflows via a large client master key or session ID.
5
Is CVE-2002-0656 exploitable over the Internet?
Yes, CVE-2002-0656 is exploitable over the Internet, making affected systems vulnerable to remote attacks.