cbcvebase.
CVE-2009-0590
published 2009-03-27

CVE-2009-0590: The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash)…

PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.19%
92.7th percentile
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 0.9.8g-16 (bookworm)openssl 0.9.8g-16 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
opensslopenssl< 0.9.8k0.9.8k
opensslopenssl>= 0 < 0.9.8g-160.9.8g-16
opensslopenssl>= 0 < 0.9.8g-160.9.8g-16
opensslopenssl>= 0 < 0.9.8g-160.9.8g-16
opensslopenssl>= 0 < 0.9.8g-160.9.8g-16

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.