LWN.net Logo

openssl: denial of service

Package(s):openssl CVE #(s):CVE-2009-0590
Created:March 31, 2009 Updated:July 27, 2011
Description: From the Ubuntu advisory: It was discovered that OpenSSL did not properly validate the length of an encoded BMPString or UniversalString when printing ASN.1 strings. If a user or automated system were tricked into processing a crafted certificate, an attacker could cause a denial of service via application crash in applications linked against OpenSSL.
Alerts:
SUSE SUSE-SU-2011:0847-1 2011-07-27
openSUSE openSUSE-SU-2011:0845-1 2011-07-27
CentOS CESA-2010:0163 2010-03-25
Red Hat RHSA-2010:0163-01 2010-03-25
CentOS CESA-2009:1335 2009-09-15
Red Hat RHSA-2009:1335-02 2009-09-02
SuSE SUSE-SR:2009:010 2009-05-12
Slackware SSA:2009-098-01 2009-04-08
Gentoo 200904-08 2009-04-07
Debian DSA-1763-1 2009-04-06
Mandriva MDVSA-2009:087 2009-04-03
rPath rPSA-2009-0057-1 2009-04-03
Ubuntu USN-750-1 2009-03-30

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds