CVE-2009-0590
published 2009-03-27CVE-2009-0590: The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash)…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.19%
92.7th percentile
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 0.9.8g-16 (bookworm) | openssl 0.9.8g-16 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| openssl | openssl | < 0.9.8k | 0.9.8k |
| openssl | openssl | >= 0 < 0.9.8g-16 | 0.9.8g-16 |
| openssl | openssl | >= 0 < 0.9.8g-16 | 0.9.8g-16 |
| openssl | openssl | >= 0 < 0.9.8g-16 | 0.9.8g-16 |
| openssl | openssl | >= 0 < 0.9.8g-16 | 0.9.8g-16 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2009-0590: NIST NVD Details: https://nvd
vendor_msrc·2020-09-08·CVSS 5.0
CVE-2009-0590 [MEDIUM] CVE-2009-0590: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2009-0590
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: openssl
BSD
FreeBSD-SA-09:08.openssl: Remotely exploitable crash in OpenSSL
bsd_advisories·2009-04-22·CVSS 5.0
CVE-2009-0590 [MEDIUM] FreeBSD-SA-09:08.openssl: Remotely exploitable crash in OpenSSL
FreeBSD-SA-09:08.openssl Security Advisory
The FreeBSD Project
Topic: Remotely exploitable crash in OpenSSL
Category: contrib
Module: openssl
Announced: 2009-04-22
Affects: All supported versions of FreeBSD.
Corrected: 2009-04-22 14:07:14 UTC (RELENG_7, 7.2-PRERELEASE)
2009-04-22 14:07:14 UTC (RELENG_7_2, 7.2-RC2)
2009-04-22 14:07:14 UTC (RELENG_7_1, 7.1-RELEASE-p5)
2009-04-22 14:07:14 UTC (RELENG_7_0, 7.0-RELEASE-p12)
2009-04-22 14:07:14 UTC (RELENG_6, 6.4-STABLE)
2009-04-22 14:07:14 UTC (RELENG_6_4, 6.4-RELEASE-p4)
2009-04-22 14:07:14 UTC (RELENG_6_3, 6.3-RELEASE-p10)
CVE Name: CVE-2009-0590
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD inc
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2009-03-30
CVE-2009-0590 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL vulnerability
It was discovered that OpenSSL did not properly validate the length of an
encoded BMPString or UniversalString when printing ASN.1 strings. If a user
or automated system were tricked into processing a crafted certificate, an
attacker could cause a denial of service via application crash in
applications linked against OpenSSL.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
openssl: ASN1 printing crash
vendor_redhat·2009-03-25·CVSS 5.0
CVE-2009-0590 [MEDIUM] openssl: ASN1 printing crash
openssl: ASN1 printing crash
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Debian
CVE-2009-0590: openssl - The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attacke...
vendor_debian·2009·CVSS 5.0
CVE-2009-0590 [MEDIUM] CVE-2009-0590: openssl - The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attacke...
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Scope: local
bookworm: resolved (fixed in 0.9.8g-16)
bullseye: resolved (fixed in 0.9.8g-16)
forky: resolved (fixed in 0.9.8g-16)
sid: resolved (fixed in 0.9.8g-16)
trixie: resolved (fixed in 0.9.8g-16)
GHSA
GHSA-pvqm-jc37-37p5: The ASN1_STRING_print_ex function in OpenSSL before 0
ghsa_unreviewed·2022-05-03
CVE-2009-0590 [MEDIUM] CWE-119 GHSA-pvqm-jc37-37p5: The ASN1_STRING_print_ex function in OpenSSL before 0
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
OSV
CVE-2009-0590: The ASN1_STRING_print_ex function in OpenSSL before 0
osv·2009-03-27·CVSS 5.0
CVE-2009-0590 [MEDIUM] CVE-2009-0590: The ASN1_STRING_print_ex function in OpenSSL before 0
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
No detection rules found.
No public exploits indexed.
Bugzilla
openssl compat mode x509 subject name injection
bugzilla·2009-07-09·CVSS 5.0
[MEDIUM] openssl compat mode x509 subject name injection
openssl compat mode x509 subject name injection
In his upcoming Blackhat paper and presentation Dan Kaminsky
highlights some more issues he has found relating to SSL hash
collisions and related vulnerabilities.
His second issue is all about inconsistencies in the interpretation of subject
x509 names in certificates. Specifically "issue 2d' is how the OpenSSL command line utility will output unescaped subject X509 lines to the standard output.
So if some utility runs the openssl application from the command line and parses the text output, and if an attacker can craft a malicious certificate
in such a way they fool a CA into signing it, they could present it to the utility and possibly fool that utility into thinking fields were different to they actually are, perhaps allowing the certif
Bugzilla
CVE-2009-0590 openssl: ASN1 printing crash
bugzilla·2009-03-26·CVSS 5.0
CVE-2009-0590 [MEDIUM] CVE-2009-0590 openssl: ASN1 printing crash
CVE-2009-0590 openssl: ASN1 printing crash
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0590 to
the following vulnerability:
ASN1 printing crash
The function ASN1_STRING_print_ex() when used to print a BMPString or
UniversalString will crash with an invalid memory access if the encoded length
of the string is illegal. (CVE-2009-0590)
Any OpenSSL application which prints out the contents of a certificate could
be affected by this bug, including SSL servers, clients and S/MIME software.
Fixed in 0.9.8k
http://cvs.openssl.org/chngview?cn=17907
Discussion:
Upstream security advisory:
http://openssl.org/news/secadv_20090325.txt
---
The impact of this flaw is limited to crash of the applications calling affected openssl function. There are currently no known appl
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.aschttp://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://marc.info/?l=bugtraq&m=124464882609472&w=2http://marc.info/?l=bugtraq&m=125017764422557&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://secunia.com/advisories/34411http://secunia.com/advisories/34460http://secunia.com/advisories/34509http://secunia.com/advisories/34561http://secunia.com/advisories/34666http://secunia.com/advisories/34896http://secunia.com/advisories/34960http://secunia.com/advisories/35065http://secunia.com/advisories/35181http://secunia.com/advisories/35380http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/36701http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://secunia.com/advisories/42467http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.aschttp://securitytracker.com/id?1021905http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1http://support.apple.com/kb/HT3865http://support.avaya.com/elmodocs2/security/ASA-2009-172.htmhttp://voodoo-circle.sourceforge.net/sa/sa-20090326-01.htmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0057http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057http://www.debian.org/security/2009/dsa-1763http://www.mandriva.com/security/advisories?name=MDVSA-2009:087http://www.openssl.org/news/secadv_20090325.txthttp://www.osvdb.org/52864http://www.php.net/archive/2009.php#id2009-04-08-1http://www.redhat.com/support/errata/RHSA-2009-1335.htmlhttp://www.securityfocus.com/archive/1/502429/100/0/threadedhttp://www.securityfocus.com/archive/1/515055/100/0/threadedhttp://www.securityfocus.com/bid/34256http://www.ubuntu.com/usn/usn-750-1http://www.vmware.com/security/advisories/VMSA-2010-0019.htmlhttp://www.vupen.com/english/advisories/2009/0850http://www.vupen.com/english/advisories/2009/1020http://www.vupen.com/english/advisories/2009/1175http://www.vupen.com/english/advisories/2009/1220http://www.vupen.com/english/advisories/2009/1548http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2010/3126https://exchange.xforce.ibmcloud.com/vulnerabilities/49431https://kb.bluecoat.com/index?page=content&id=SA50https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlhttps://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10198https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6996ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.aschttp://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://marc.info/?l=bugtraq&m=124464882609472&w=2http://marc.info/?l=bugtraq&m=125017764422557&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://secunia.com/advisories/34411http://secunia.com/advisories/34460http://secunia.com/advisories/34509http://secunia.com/advisories/34561http://secunia.com/advisories/34666http://secunia.com/advisories/34896http://secunia.com/advisories/34960http://secunia.com/advisories/35065http://secunia.com/advisories/35181http://secunia.com/advisories/35380http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/36701http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://secunia.com/advisories/42467http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.aschttp://securitytracker.com/id?1021905http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1http://support.apple.com/kb/HT3865http://support.avaya.com/elmodocs2/security/ASA-2009-172.htmhttp://voodoo-circle.sourceforge.net/sa/sa-20090326-01.htmlhttp://wiki.rpath.com/Advisories:rPSA-2009-0057http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057http://www.debian.org/security/2009/dsa-1763http://www.mandriva.com/security/advisories?name=MDVSA-2009:087http://www.openssl.org/news/secadv_20090325.txthttp://www.osvdb.org/52864
+ 20 more references
2009-03-27
Published