CVE
- Id
- 5049
- CVE No.
- CVE-2002-0659
- Status
- Candidate
- Description
- The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat
- Comments
- Cox> ADDREF:RHSA-2002:163 RHSA-2002:184 | add "and possibly arbitrary code execution" | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship.