VulnerabilityModified
CVE-2009-0590
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid…
MEDIUM 5.0EPSS 6.71%
Does this matter?
Lower severity and a low EPSS score (6.71%). Track it; it rarely justifies an emergency change on its own.
Description
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 6.71% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- openssl/openssl · debian/debian linux
- Source
- secalert@redhat.com
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.ascThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlMailing List, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2010/000082.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=124464882609472&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=125017764422557&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=127678688104458&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/34411Third Party Advisory
- http://secunia.com/advisories/34460Third Party Advisory
- http://secunia.com/advisories/34509Third Party Advisory
- http://secunia.com/advisories/34561Third Party Advisory
- http://secunia.com/advisories/34666Third Party Advisory
- http://secunia.com/advisories/34896Third Party Advisory
- http://secunia.com/advisories/34960Third Party Advisory
- http://secunia.com/advisories/35065Third Party Advisory
- http://secunia.com/advisories/35181Third Party Advisory
- http://secunia.com/advisories/35380Third Party Advisory
- http://secunia.com/advisories/35729Third Party Advisory
- http://secunia.com/advisories/36533Third Party Advisory
- http://secunia.com/advisories/36701Third Party Advisory
- http://secunia.com/advisories/38794Third Party Advisory
- http://secunia.com/advisories/38834Third Party Advisory
- http://secunia.com/advisories/42467Third Party Advisory
- http://secunia.com/advisories/42724Third Party Advisory
- http://secunia.com/advisories/42733Third Party Advisory
- http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.ascThird Party Advisory
- http://securitytracker.com/id?1021905Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.