CVE-2009-3245
published 2010-03-05CVE-2009-3245: OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3)…
PriorityP432critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.73%
93.2th percentile
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8m-1 (bookworm) | openssl 0.9.8m-1 (bookworm) |
| openssl | openssl | <= 0.9.8l | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8m-1 | 0.9.8m-1 |
| openssl | openssl | >= 0 < 0.9.8m-1 | 0.9.8m-1 |
| openssl | openssl | >= 0 < 0.9.8m-1 | 0.9.8m-1 |
| openssl | openssl | >= 0 < 0.9.8m-1 | 0.9.8m-1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2010-10-07·CVSS 10.0
CVE-2009-3245 [CRITICAL] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
It was discovered that OpenSSL incorrectly handled return codes from the
bn_wexpand function calls. A remote attacker could trigger this flaw in
services that used SSL to cause a denial of service or possibly execute
arbitrary code with application privileges. This issue only affected Ubuntu
6.06 LTS, 8.04 LTS, 9.04 and 9.10. (CVE-2009-3245)
It was discovered that OpenSSL incorrectly handled certain private keys
with an invalid prime. A remote attacker could trigger this flaw in
services that used SSL to cause a denial of service or possibly execute
arbitrary code with application privileges. The default compiler options
for affected releases should reduce the vulnerability to a denial of
service. (CVE-2010-2939)
Instructions: After a standard system updat
Red Hat
openssl: missing bn_wexpand return value checks
vendor_redhat·2010-02-23·CVSS 10.0
CVE-2009-3245 [CRITICAL] CWE-252 openssl: missing bn_wexpand return value checks
openssl: missing bn_wexpand return value checks
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Debian
CVE-2009-3245: openssl - OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand fun...
vendor_debian·2009·CVSS 10.0
CVE-2009-3245 [CRITICAL] CVE-2009-3245: openssl - OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand fun...
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Scope: local
bookworm: resolved (fixed in 0.9.8m-1)
bullseye: resolved (fixed in 0.9.8m-1)
forky: resolved (fixed in 0.9.8m-1)
sid: resolved (fixed in 0.9.8m-1)
trixie: resolved (fixed in 0.9.8m-1)
GHSA
GHSA-c5qh-p8w9-vjq7: OpenSSL before 0
ghsa_unreviewed·2022-05-02
CVE-2009-3245 [HIGH] CWE-20 GHSA-c5qh-p8w9-vjq7: OpenSSL before 0
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
OSV
CVE-2009-3245: OpenSSL before 0
osv·2010-03-05·CVSS 10.0
CVE-2009-3245 [CRITICAL] CVE-2009-3245: OpenSSL before 0
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
No detection rules found.
No public exploits indexed.
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.aschttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://marc.info/?l=bugtraq&m=127128920008563&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://marc.info/?l=openssl-cvs&m=126692159706582&w=2http://marc.info/?l=openssl-cvs&m=126692170906712&w=2http://marc.info/?l=openssl-cvs&m=126692180606861&w=2http://packetstormsecurity.com/files/153392/ABB-HMI-Outdated-Software-Components.htmlhttp://secunia.com/advisories/37291http://secunia.com/advisories/38761http://secunia.com/advisories/39461http://secunia.com/advisories/39932http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://support.apple.com/kb/HT4723http://www.mandriva.com/security/advisories?name=MDVSA-2010:076http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/bid/38562http://www.ubuntu.com/usn/USN-1003-1http://www.vupen.com/english/advisories/2010/0839http://www.vupen.com/english/advisories/2010/0916http://www.vupen.com/english/advisories/2010/0933http://www.vupen.com/english/advisories/2010/1216https://kb.bluecoat.com/index?page=content&id=SA50https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlhttps://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11738https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6640https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9790http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.aschttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://marc.info/?l=bugtraq&m=127128920008563&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://marc.info/?l=openssl-cvs&m=126692159706582&w=2http://marc.info/?l=openssl-cvs&m=126692170906712&w=2http://marc.info/?l=openssl-cvs&m=126692180606861&w=2http://packetstormsecurity.com/files/153392/ABB-HMI-Outdated-Software-Components.htmlhttp://secunia.com/advisories/37291http://secunia.com/advisories/38761http://secunia.com/advisories/39461http://secunia.com/advisories/39932http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://support.apple.com/kb/HT4723http://www.mandriva.com/security/advisories?name=MDVSA-2010:076http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/bid/38562http://www.ubuntu.com/usn/USN-1003-1http://www.vupen.com/english/advisories/2010/0839http://www.vupen.com/english/advisories/2010/0916http://www.vupen.com/english/advisories/2010/0933http://www.vupen.com/english/advisories/2010/1216https://kb.bluecoat.com/index?page=content&id=SA50https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlhttps://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11738https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6640https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9790
2010-03-05
Published