PT-2009-6752 · Openssl+1 · Openssl+1

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0789

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8k
Description The issue is related to the improper handling of a malformed ASN.1 structure in OpenSSL, which can be exploited remotely. This can lead to a denial of service, causing invalid memory access and application crash, by placing the malformed structure in the public key of a certificate, such as an RSA public key.
Recommendations For versions prior to 0.9.8k, update to version 0.9.8k or later to resolve the issue. As a temporary workaround, consider restricting access to certificates with potentially malformed ASN.1 structures until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05174
BDU:2015-05175
CVE-2009-0789
HPSBUX02435
OPENSUSE-SU-2024:11127-1

Affected Products

Hp-Ux
Openssl