CVE
- Id
- 4476
- CVE No.
- CVE-2002-0082
- Status
- Entry
- Description
- The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
21955 | 4476 | CVE-2002-0082 | BUGTRAQ:20020227 mod_ssl Buffer Overflow Condition (Update Available) | View |
21956 | 4476 | CVE-2002-0082 | URL:http://online.securityfocus.com/archive/1/258646 | View |
21957 | 4476 | CVE-2002-0082 | BUGTRAQ:20020301 Apache-SSL buffer overflow (fix available) | View |
21958 | 4476 | CVE-2002-0082 | URL:http://marc.info/?l=bugtraq&m=101518491916936&w=2 | View |
21959 | 4476 | CVE-2002-0082 | BUGTRAQ:20020304 Apache-SSL 1.3.22+1.47 - update to security fix | View |
21960 | 4476 | CVE-2002-0082 | URL:http://marc.info/?l=bugtraq&m=101528358424306&w=2 | View |
21961 | 4476 | CVE-2002-0082 | CONFIRM:http://www.apacheweek.com/issues/02-03-01#security | View |
21962 | 4476 | CVE-2002-0082 | BUGTRAQ:20020228 TSLSA-2002-0034 - apache | View |
21963 | 4476 | CVE-2002-0082 | ENGARDE:ESA-20020301-005 | View |
21964 | 4476 | CVE-2002-0082 | URL:http://www.linuxsecurity.com/advisories/other_advisory-1923.html | View |
21965 | 4476 | CVE-2002-0082 | CONECTIVA:CLA-2002:465 | View |
21966 | 4476 | CVE-2002-0082 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000465 | View |
21967 | 4476 | CVE-2002-0082 | MANDRAKE:MDKSA-2002:020 | View |
21968 | 4476 | CVE-2002-0082 | URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-020.php | View |
21969 | 4476 | CVE-2002-0082 | REDHAT:RHSA-2002:041 | View |
21970 | 4476 | CVE-2002-0082 | URL:http://www.redhat.com/support/errata/RHSA-2002-041.html | View |
21971 | 4476 | CVE-2002-0082 | REDHAT:RHSA-2002:042 | View |
21972 | 4476 | CVE-2002-0082 | URL:http://www.redhat.com/support/errata/RHSA-2002-042.html | View |
21973 | 4476 | CVE-2002-0082 | REDHAT:RHSA-2002:045 | View |
21974 | 4476 | CVE-2002-0082 | URL:http://www.redhat.com/support/errata/RHSA-2002-045.html | View |
21975 | 4476 | CVE-2002-0082 | DEBIAN:DSA-120 | View |
21976 | 4476 | CVE-2002-0082 | URL:http://www.debian.org/security/2002/dsa-120 | View |
21977 | 4476 | CVE-2002-0082 | HP:HPSBTL0203-031 | View |
21978 | 4476 | CVE-2002-0082 | URL:http://www.securityfocus.com/advisories/3965 | View |
21979 | 4476 | CVE-2002-0082 | HP:HPSBUX0204-190 | View |
21980 | 4476 | CVE-2002-0082 | URL:http://www.securityfocus.com/advisories/4008 | View |
21981 | 4476 | CVE-2002-0082 | CALDERA:CSSA-2002-011.0 | View |
21982 | 4476 | CVE-2002-0082 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-011.0.txt | View |
21983 | 4476 | CVE-2002-0082 | COMPAQ:SSRT0817 | View |
21984 | 4476 | CVE-2002-0082 | URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0817.shtml | View |
21985 | 4476 | CVE-2002-0082 | BID:4189 | View |
21986 | 4476 | CVE-2002-0082 | URL:http://www.securityfocus.com/bid/4189 | View |
21987 | 4476 | CVE-2002-0082 | XF:apache-modssl-bo(8308) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63722 | JVNDB-2002-000049 | Apache HTTP Server の Mod_SSL/Apache-SSL におけるバッファオーバーフローの脆弱性 | Apache HTTP Server 用の SSL モジュールパッケージ mod_ssl 、Apache-SSL において非常に大量の SSL セッションが確立された場合、バッファオーバーフローが発生する脆弱性が存在します。 | CVE-2002-0082 | 4476 | 7.5 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000049.html | View |