CVE-2009-0590
OpenSSL < 0.9.8k - Denial of Service via ASN1_STRING_print_ex Invalid Memory Access
Title source: llmDescription
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
References (60)
Core 60
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=124464882609472&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34896
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2010-0019.html
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0850
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1021905
Third Party Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:087
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1175
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42724
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502429/100/0/threaded
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html
Broken Link x_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2009-0057
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2009/dsa-1763
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38794
Third Party Advisory mailing-list
x_refsource_mlist
http://lists.vmware.com/pipermail/security-announce/2010/000082.html
Patch, Third Party Advisory x_refsource_confirm
http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34960
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html
Broken Link x_refsource_misc
http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34666
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-750-1
Third Party Advisory vendor-advisory
x_refsource_freebsd
http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1020
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35729
Third Party Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1335.html
Broken Link vdb-entry
x_refsource_osvdb
http://www.osvdb.org/52864
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34561
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35380
Mailing List, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=127678688104458&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42467
Mailing List, Third Party Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35065
Third Party Advisory mailing-list
x_refsource_mlist
https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10198
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36533
Third Party Advisory x_refsource_confirm
http://www.php.net/archive/2009.php#id2009-04-08-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34411
Third Party Advisory vendor-advisory
x_refsource_netbsd
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/515055/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34509
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49431
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35181
Broken Link vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38834
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6996
Third Party Advisory mailing-list
x_refsource_mlist
https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3126
Third Party Advisory x_refsource_confirm
http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3865
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1220
Vendor Advisory x_refsource_confirm
http://www.openssl.org/news/secadv_20090325.txt
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1548
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36701
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2009-172.htm
Mailing List, Third Party Advisory vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=125017764422557&w=2
Third Party Advisory x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA50
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34460
Patch, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34256
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42733
Permissions Required vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0528
Scores
EPSS
0.1002
EPSS Percentile
93.2%
Details
CWE
CWE-119
Status
published
Products (3)
debian/debian_linux
4.0
debian/debian_linux
5.0
openssl/openssl
< 0.9.8k
Published
Mar 27, 2009
Tracked Since
Feb 18, 2026