CVE-2009-0590

Publication date 27 March 2009

Last updated 24 July 2024


Ubuntu priority

The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.

Status

Package Ubuntu Release Status
openssl 8.10 intrepid
Fixed 0.9.8g-10.1ubuntu2.2
8.04 LTS hardy
Fixed 0.9.8g-4ubuntu3.5
7.10 gutsy
Fixed 0.9.8e-5ubuntu3.4
6.06 LTS dapper
Fixed 0.9.8a-7ubuntu0.7

References

Related Ubuntu Security Notices (USN)

    • USN-750-1
    • OpenSSL vulnerability
    • 30 March 2009

Other references