CVE-2002-0082

The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache-ssl:apache-ssl:1.45:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.46:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.42:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.44:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.40:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.41:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.1:*:*:*:*:*:*:*

Information

Published : 2002-03-14 21:00

Updated : 2016-10-17 19:16


NVD link : CVE-2002-0082

Mitre link : CVE-2002-0082


JSON object : View

Advertisement

dedicated server usa

Products Affected

apache-ssl

  • apache-ssl

mod_ssl

  • mod_ssl