CVE-2009-0590
openssl openssl097 - denial of service
EPSS 6.2%
描述
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
如何修補 CVE-2009-0590
要修補 CVE-2009-0590,請將受影響套件升級到下列已修補版本。
- Debian/openssl—升級至 0.9.8g-16 或更新版本
- Debian/openssl—升級至 0.9.8c-4etch5 或更新版本
- Debian/openssl097—升級至 0.9.7k-3.1etch3 或更新版本
CVE-2009-0590 正在被利用嗎?
中等 — EPSS 為 6.2%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 0.9.8g-16
- from 0, < 0.9.8c-4etch5
- from 0, < 0.9.7k-3.1etch3