CVE-2009-0590
EPSS 10.0%openssl openssl097 - denial of service
Published: 3/27/2009Modified: 4/28/2026
Description
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Affected packages (3)
- Debian/opensslfrom 0, < 0.9.8g-16
- Debian/opensslfrom 0, < 0.9.8c-4etch5
- Debian/openssl097from 0, < 0.9.7k-3.1etch3