CVE-2002-0659

OpenSSL 0.9.6d and earlier, 0.9.7-beta2 and earlier - Denial of Service via Invalid ASN1 Encodings

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0659. PoCs published by Syzop.

AI-analyzed exploit summary This is a brute-force exploit for OpenSSL ASN.1 parsing vulnerabilities (CVE-2002-0659). It sends corrupted client certificates to an SSL server, potentially causing a denial of service or arbitrary code execution. The code includes functions to send malformed SSL handshakes and corrupt ASN.1 data.

Description

The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Syzop · cremotemultiple
https://www.exploit-db.com/exploits/23199

This is a brute-force exploit for OpenSSL ASN.1 parsing vulnerabilities (CVE-2002-0659). It sends corrupted client certificates to an SSL server, potentially causing a denial of service or arbitrary code execution. The code includes functions to send malformed SSL handshakes and corrupt ASN.1 data.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Racy
Target: OpenSSL <=0.9.6j and <=0.9.7b
No auth needed
Prerequisites: Network access to target SSL server · Target server must be running vulnerable OpenSSL version
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (11)

Core 11
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/748355
Various Sources vendor-advisory x_refsource_caldera
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txt
US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-23.html
Various Sources vendor-advisory x_refsource_caldera
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.1.txt
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9718.php
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000516
Various Sources vendor-advisory x_refsource_freebsd
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.asc
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2002-164.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2002-161.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2002-160.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5366

Scores

EPSS 0.3604
EPSS Percentile 98.3%

Details

Status published
Products (33)
apple/mac_os_x 10.0
apple/mac_os_x 10.0.1
apple/mac_os_x 10.0.2
apple/mac_os_x 10.0.3
apple/mac_os_x 10.0.4
apple/mac_os_x 10.1
apple/mac_os_x 10.1.1
apple/mac_os_x 10.1.2
apple/mac_os_x 10.1.3
apple/mac_os_x 10.1.4
... and 23 more
Published Aug 12, 2002
Tracked Since Feb 18, 2026