PT-2009-6751 · Openssl+2 · Openssl+2
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2009-0590
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 0.9.8k
Description
The issue allows remote attackers to cause a denial of service, potentially leading to invalid memory access and application crash, via vectors that trigger printing of a BMPString or UniversalString with an invalid encoded length. Exploitation of the vulnerabilities may lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations
For versions prior to 0.9.8k, update to version 0.9.8k or later to resolve the issue. As a temporary workaround, consider restricting access to the
ASN1 STRING print ex function until a patch is available.Exploit
Fix
DoS
Buffer Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Openssl
Red Hat