Published: 15/03/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 766
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The dbm and shm session cache code in mod_ssl prior to 2.8.7-1.3.23, and Apache-SSL prior to 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote malicious users to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.

Vendor Advisories

Ed Moyle recently found a buffer overflow in Apache-SSL and mod_ssl With session caching enabled, mod_ssl will serialize SSL session variables to store them for later use These variables were stored in a buffer of a fixed size without proper boundary checks To exploit the overflow, the server must be configured to require client certificates, an ...


/* * E-DB Note: Updating OpenFuck Exploit ~ paulsecgithubio/blog/2014/04/14/updating-openfuck-exploit/ * * OF version r00t VERY PRIV8 spabam * Compile with: gcc -o OpenFuck OpenFuckc -lcrypto * objdump -R /usr/sbin/httpd|grep free to get more targets * #hackarena ircbrasnetorg */ #include <arpa/ineth> #include <netinet ...
/* source: wwwsecurityfocuscom/bid/5363/info A buffer-overflow vulnerability has been reported in some versions of OpenSSL The issue occurs in the handling of the client key value during the negotiation of the SSLv2 protocol A malicious client may be able to exploit this vulnerability to execute arbitrary code as the vulnerable server ...
/* * OF version r00t VERY PRIV8 spabam * Version: v304 * Requirements: libssl-dev * Compile with: gcc -o OpenFuck OpenFuckc -lcrypto * objdump -R /usr/sbin/httpd|grep free to get more targets * #hackarena ircbrasnetorg * Note: if required, host ptrace and replace wget target */ #include <arpa/ineth> #include <netinet/inh&g ...

