← All CVEs

CVE-2002-0082

high · 7.5

The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.

7.5
CVSS
29.7%
EPSS (exploit prob.)
98th
EPSS percentile
2002-03-15
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
apache-sslapache-ssl1.40
apache-sslapache-ssl1.41
apache-sslapache-ssl1.42
apache-sslapache-ssl1.44
apache-sslapache-ssl1.45
apache-sslapache-ssl1.46
mod_sslmod_ssl2.7.1
mod_sslmod_ssl2.8
mod_sslmod_ssl2.8.1
mod_sslmod_ssl2.8.2
mod_sslmod_ssl2.8.3
mod_sslmod_ssl2.8.4
mod_sslmod_ssl2.8.5
mod_sslmod_ssl2.8.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0082