CVE-2009-3245: Input Validation
OpenSSL before 0.9.8m does not check for a NULL return value from bnwexpand function calls in (1) crypto/bn/bndiv.c, (2) crypto/bn/bngf2m.c, (3) crypto/ec/ec2smpl.c, and (4) engines/eubsec.c, which has unspecified impact and context-dependent attack vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3245?
The severity of CVE-2009-3245 is not explicitly rated but involves potential unspecified impacts due to null return value checks.
How do I fix CVE-2009-3245?
To fix CVE-2009-3245, upgrade your OpenSSL version to 0.9.8m or later.
What software is affected by CVE-2009-3245?
CVE-2009-3245 affects OpenSSL versions prior to 0.9.8m, including 0.9.8a through 0.9.8l.
What attack vectors are associated with CVE-2009-3245?
CVE-2009-3245 has context-dependent attack vectors which may exploit functions without proper null checks.
Is CVE-2009-3245 still a concern today?
CVE-2009-3245 remains a concern for systems running older versions of OpenSSL, especially those still in use.