OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2003-10-08T04:00:00

Updated: 2016-10-17T13:57:01

Reserved: 2003-10-06T00:00:00


Link: CVE-2002-1568

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2003-11-17T05:00:00.000

Modified: 2016-10-18T02:27:13.107


Link: CVE-2002-1568

JSON object: View

cve-icon Redhat Information

No data.