CVE-2009-0789: Medium severity OpenSSL OpenSSL vulnerability
OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0789?
CVE-2009-0789 is considered a high severity vulnerability as it can lead to denial of service and application crashes.
How do I fix CVE-2009-0789?
To fix CVE-2009-0789, upgrade OpenSSL to a version that is 0.9.8k or later.
Who is affected by CVE-2009-0789?
CVE-2009-0789 affects OpenSSL versions prior to 0.9.8k on various platforms including WIN64.
What types of attacks can exploit CVE-2009-0789?
CVE-2009-0789 can be exploited through malformed ASN.1 structures in public keys, causing memory access violations.
What are the potential consequences of CVE-2009-0789?
The consequences of CVE-2009-0789 include crashes of applications utilizing affected OpenSSL versions, leading to service disruptions.