|
|
| |
|
| |
openssl: several vulnerabilities
| Package(s): | openssl |
CVE #(s): | CVE-2009-0789
CVE-2009-0591
|
| Created: | April 8, 2009 |
Updated: | July 27, 2011 |
| Description: |
From the CVE entries:
OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key. CVE-2009-0789
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid. CVE-2009-0591 |
| Alerts: |
|
( Log in to post comments)
|
|
|