MNBSD-2009-4: OpenSSL ASN1_STRING_print_ex length validation flaw

Severity: Unknown

Affected Package: openssl

Summary: OpenSSL ASN1_STRING_print_ex length validation flaw

Description

The OpenSSL function ASN1_STRING_print_ex does not properly validate the lengths of BMPString or UniversalString objects before attempting to print them, which could lead to a denial of service. The fix was included in MidnightBSD 0.2.1-RELEASE-p8 and 0.3-CURRENT. This corresponds to FreeBSD-SA-09:08.openssl.

Affected Versions

openssl

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2009-0590

Published: April 22, 2009
Last Modified: April 22, 2009