|
|
Subscribe / Log in / New account

OpenSSL remotely-exploitable buffer overflow vulnerabilities

Package(s):OpenSSL CVE #(s):CAN-2002-0655 CAN-2002-0656 CAN-2002-0657 CAN-2002-0659
Created:July 30, 2002 Updated:September 24, 2002
Description: Four remotely-exploitable buffer overflows were found in OpenSSL versions 0.9.7 and 0.9.6d and earlier by a DARPA sponsored security audit. Both client and server applications are affected. The vulnerabilities are described in this security alert from the OpenSSL team.

A nasty exploit for one of the vulnerabilities is described in CERT Advisory CA-2002-27 Apache/mod_ssl Worm.

Compromise by the Apache/mod_ssl worm indicates that a remote attacker can execute arbitrary code as the apache user on the victim system. It may be possible for an attacker to subsequently leverage a local privilege escalation exploit in order to gain root access to the victim system. Furthermore, the DDoS capabilities included in the Apache/mod_ssl worm allow victim systems to be used as platforms to attack other systems.

If you haven't already, applying an update is a very good thing to do today.

Mitel Networks has an update available which closes this vulnerabilty for their SME Server software.

CERT Advisory CA-2002-23 Multiple Vulnerabilities In OpenSSL

Alerts:
SuSE SuSE-SA:2002:033 openssl/Slapper 2002-09-19
Debian DSA-136-2 openssl094 2002-09-15
Yellow Dog YDU-20020810-1 openssl 2002-08-10
Conectiva CLA-2002:516 openssl 2002-08-08
EnGarde ESA-20020807-020 OpenSSL 2002-08-07
Mandrake MDKSA-2002:046-1 openssl 2002-08-06
Red Hat RHSA-2002:160-21 OpenSSL 2002-08-05
Eridani ERISA-2002:034 openssl 2002-08-06
Yellow Dog YDU-20020801-3 openssl 2002-08-01
SCO Group CSSA-2002-033.0 OpenSSL 2002-07-31
Gentoo openssl-20020730 openssl 2002-07-30
Eridani ERISA-2002:033 openssl 2002-07-30
SuSE SuSE-SA:2002:027 openssl 2002-07-30
Mandrake MDKSA-2002:046 openssl 2002-07-30
Conectiva CLA-2002:513 openssl 2002-07-31
Red Hat RHSA-2002:155-11 OpenSSL 2002-07-29
Trustix 2002-0063 openssl 2002-07-29
OpenPKG OpenPKG-SA-2002.008 openssl 2002-07-30
EnGarde ESA-20020730-019 OpenSSL 2002-07-30
Debian DSA-136-1 openssl 2002-07-30

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds