CLA-2002:516Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000516 CVE-2002-0659
OpenSSL - ASN.1 Parsing
Record summary
CVE-2002-0659 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenSSL - ASN.1 ParsingExploitDB exploitby SyzopNot analyzed1 file
References
9RHSA-2002:160Vendor advisory
http://rhn.redhat.com/errata/RHSA-2002-160.html RHSA-2002:161Vendor advisory
http://rhn.redhat.com/errata/RHSA-2002-161.html RHSA-2002:164Vendor advisory
http://rhn.redhat.com/errata/RHSA-2002-164.html CA-2002-23Third-party advisory
http://www.cert.org/advisories/CA-2002-23.html openssl-asn1-parser-dos(9718)vdb entry
http://www.iss.net/security_center/static/9718.php VU#748355Third-party advisory
http://www.kb.cert.org/vuls/id/748355 5366vdb entry
http://www.securityfocus.com/bid/5366 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0659