Vulnerability Intelligence Report
CVE-2009-3245
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:6.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| openssl | openssl | 0.9.8, 0.9.8a, 0.9.8b, 0.9.8c, 0.9.8d, 0.9.8e, 0.9.8f, 0.9.8g, 0.9.8h, 0.9.8i, 0.9.8j, 0.9.8k |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
6.732%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2009-09-18T00:00:00 |
| Published | 2010-03-05T19:00:00 |
| Patch Date | 2010-02-23 |
| Last Updated | 2024-08-07T06:22:24 |
Community Chatter & Buzz