cbcvebase.
CVE-2009-3245
published 2010-03-05

CVE-2009-3245: OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3)…

PriorityP432critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.73%
93.2th percentile
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianopenssl< openssl 0.9.8m-1 (bookworm)openssl 0.9.8m-1 (bookworm)
opensslopenssl<= 0.9.8l
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl>= 0 < 0.9.8m-10.9.8m-1
opensslopenssl>= 0 < 0.9.8m-10.9.8m-1
opensslopenssl>= 0 < 0.9.8m-10.9.8m-1
opensslopenssl>= 0 < 0.9.8m-10.9.8m-1

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.