← Back to CVE List
Vulnerability Intelligence Report

CVE-2009-3245

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:6.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
openssl openssl 0.9.8, 0.9.8a, 0.9.8b, 0.9.8c, 0.9.8d, 0.9.8e, 0.9.8f, 0.9.8g, 0.9.8h, 0.9.8i, 0.9.8j, 0.9.8k

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.732%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2009-09-18T00:00:00
Published2010-03-05T19:00:00
Patch Date2010-02-23
Last Updated2024-08-07T06:22:24

LINK COPIED TO CLIPBOARD