CVE-2002-0082

The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache-ssl:apache-ssl:1.40:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.41:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.42:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.44:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.45:*:*:*:*:*:*:*
cpe:2.3:a:apache-ssl:apache-ssl:1.46:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:mod_ssl:mod_ssl:2.8.6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2002-03-15 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2002-0082

Mitre link : CVE-2002-0082

CVE.ORG link : CVE-2002-0082


JSON object : View

Products Affected

mod_ssl

  • mod_ssl

apache-ssl

  • apache-ssl