Unrated severityNVD Advisory· Published Nov 17, 2003· Updated Jun 16, 2026
CVE-2002-1568
CVE-2002-1568
Description
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
Affected products
2cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*
- (no CPE)range: =0.9.6e
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- cvs.openssl.org/chngviewnvdPatchVendor Advisory
- marc.infonvd
- www.ebitech.sk/patrik/SA/SA-20031002.txtnvd
News mentions
0No linked articles in our index yet.