OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2003-10-08T04:00:00

Updated: 2024-08-08T03:26:29.118Z

Reserved: 2003-10-06T00:00:00

Link: CVE-2002-1568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-11-17T05:00:00.000

Modified: 2016-10-18T02:27:13.107

Link: CVE-2002-1568

cve-icon Redhat

Severity : Important

Publid Date: 2003-10-02T00:00:00Z

Links: CVE-2002-1568 - Bugzilla