CVE-2009-3245
Published Mar 5, 2010
Last updated 7 years ago
Overview
- Description
- OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-20
Social media
- Hype score
- Not currently trending
Vendor comments
- Red HatRed Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2009-3245 This issue was fixed in openssl packages in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2010-0162.html This issue was fixed in openssl096b packages in Red Hat Enterprise Linux 3 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0173.html The Red Hat Security Response Team has rated this issue as having low security impact on openssl packages in Red Hat Enterprise Linux 3 and 4, a future update may address this flaw.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81FB3B26-CC83-4FA5-BDE1-05F35AB99741", "versionEndIncluding": "0.9.8l" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A4E446D-B9D3-45F2-9722-B41FA14A6C31" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF4EA988-FC80-4170-8933-7C6663731981" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64F8F53B-24A1-4877-B16E-F1917C4E4E81" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75D3ACD5-905F-42BB-BE1A-8382E9D823BF" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "766EA6F2-7FA4-4713-9859-9971CCD2FDCB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EFBC30B7-627D-48DC-8EF0-AE8FA0C6EDBA" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BB38AEA-BAF0-4920-9A71-747C24444770" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F33EA2B-DE15-4695-A383-7A337AC38908" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "261EE631-AB43-44FE-B02A-DFAAB8D35927" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA0E0BBF-D0BE-41A7-B9BB-C28F01000BC0" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A1365ED-4651-4AB2-A64B-43782EA2F0E8" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC82690C-DCED-47BA-AA93-4D0C9E95B806" } ], "operator": "OR" } ] } ]