openssl: ASN1 printing crash
Published Mar 27, 2009
5.0
MEDIUMCVSS 2.0
EPSS 6.71%
Description
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Affected products
No data.
Configuration 2
- 4.0
- 5.0
No data.
Red Hat Enterprise Linux 3
openssl-0:0.9.7a-33.26
Fixed · RHSA-2010:0163
Red Hat Enterprise Linux 4
openssl-0:0.9.7a-43.17.el4_8.5
Fixed · RHSA-2010:0163
Red Hat Enterprise Linux 5
openssl-0:0.9.8e-12.el5
Fixed · RHSA-2009:1335
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | openssl-0:0.9.7a-33.26 | Fixed | RHSA-2010:0163 |
| Red Hat Enterprise Linux 4 | openssl-0:0.9.7a-43.17.el4_8.5 | Fixed | RHSA-2010:0163 |
| Red Hat Enterprise Linux 5 | openssl-0:0.9.8e-12.el5 | Fixed | RHSA-2009:1335 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.71% (0.06709) | 93.72th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.19% (0.06194) | 92.57th | v5 (v2026.06.15) |
| Dec 28, 2025 | 10.02% (0.10016) | 92.81th | v4 (v2025.03.14) |
| Dec 27, 2025 | 11.38% (0.11381) | 93.37th | v4 (v2025.03.14) |
| Oct 28, 2025 | 10.02% (0.10016) | 92.72th | v4 (v2025.03.14) |
| Oct 27, 2025 | 11.38% (0.11381) | 93.27th | v4 (v2025.03.14) |
| Oct 1, 2025 | 10.02% (0.10016) | 92.82th | v4 (v2025.03.14) |
| Jul 30, 2025 | 11.38% (0.11381) | 93.27th | v4 (v2025.03.14) |
| May 21, 2025 | 10.02% (0.10016) | 92.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 12.92% (0.12919) | 93.43th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.07% (0.21067) | 92.89th | v4 (v2025.03.14) |
| Mar 19, 2025 | 12.92% (0.12919) | 93.19th | v4 (v2025.03.14) |
| Mar 17, 2025 | 11.41% (0.11408) | 93.03th | v4 (v2025.03.14) |
| Dec 17, 2024 | 38.34% (0.38341) | 97.24th | v3 (v2023.03.01) |
| Mar 3, 2024 | 27.07% (0.27074) | 96.63th | v3 (v2023.03.01) |
| Dec 16, 2023 | 21.06% (0.21064) | 95.95th | v3 (v2023.03.01) |
| Nov 5, 2023 | 17.32% (0.17323) | 95.53th | v3 (v2023.03.01) |
| Sep 25, 2023 | 9.63% (0.09631) | 94.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 7.04% (0.07039) | 92.87th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Jul 18, 2022 | 7.56% (0.07559) | 92.47th | v2 (v2022.01.01) |
| Jul 17, 2022 | 4.36% (0.04358) | 87.36th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
References (64)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc vendor-advisoryx_refsource_NETBSDThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLISTThird Party Advisory
- http://marc.info/?l=bugtraq&m=124464882609472&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=125017764422557&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=127678688104458&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://secunia.com/advisories/34411 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34460 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34509 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34561 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34666 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34896 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34960 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35065 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35181 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35380 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35729 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/36533 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/36701 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/42467 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/42724 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/42733 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- http://securitytracker.com/id?1021905 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847 x_refsource_CONFIRMPatchThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.apple.com/kb/HT3865 x_refsource_CONFIRMThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-172.htm x_refsource_CONFIRMThird Party Advisory
- http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html x_refsource_CONFIRMThird Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2009-0057 x_refsource_CONFIRMBroken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057 x_refsource_MISCBroken Link
- http://www.debian.org/security/2009/dsa-1763 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:087 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openssl.org/news/secadv_20090325.txt x_refsource_CONFIRMVendor Advisory
- http://www.osvdb.org/52864 vdb-entryx_refsource_OSVDBBroken Link
- http://www.php.net/archive/2009.php#id2009-04-08-1 x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1335.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/502429/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/515055/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/34256 vdb-entryx_refsource_BIDPatchThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-750-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2010-0019.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2009/0850 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1020 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1175 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1220 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1548 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2010/3126 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2009-0590 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=492304 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49431 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://kb.bluecoat.com/index?page=content&id=SA50 x_refsource_CONFIRMThird Party Advisory
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-0590
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10198 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6996 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-0590
| Link | Providers | Tags |
|---|---|---|
| ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc | vendor-advisoryx_refsource_NETBSDThird Party Advisory | |
| http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html | vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.vmware.com/pipermail/security-announce/2010/000082.html | mailing-listx_refsource_MLISTThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=124464882609472&w=2 | vendor-advisoryx_refsource_HPMailing ListThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=125017764422557&w=2 | vendor-advisoryx_refsource_HPMailing ListThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=127678688104458&w=2 | vendor-advisoryx_refsource_HPMailing ListThird Party Advisory | |
| http://secunia.com/advisories/34411 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34460 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34509 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34561 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34666 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34896 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/34960 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/35065 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/35181 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/35380 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/35729 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/36533 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/36701 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/38794 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/38834 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/42467 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/42724 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/42733 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc | vendor-advisoryx_refsource_FREEBSDThird Party Advisory | |
| http://securitytracker.com/id?1021905 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847 | x_refsource_CONFIRMPatchThird Party Advisory | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://support.apple.com/kb/HT3865 | x_refsource_CONFIRMThird Party Advisory | |
| http://support.avaya.com/elmodocs2/security/ASA-2009-172.htm | x_refsource_CONFIRMThird Party Advisory | |
| http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html | x_refsource_CONFIRMThird Party Advisory | |
| http://wiki.rpath.com/Advisories:rPSA-2009-0057 | x_refsource_CONFIRMBroken Link | |
| http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057 | x_refsource_MISCBroken Link | |
| http://www.debian.org/security/2009/dsa-1763 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2009:087 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.openssl.org/news/secadv_20090325.txt | x_refsource_CONFIRMVendor Advisory | |
| http://www.osvdb.org/52864 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.php.net/archive/2009.php#id2009-04-08-1 | x_refsource_CONFIRMThird Party Advisory | |
| http://www.redhat.com/support/errata/RHSA-2009-1335.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.securityfocus.com/archive/1/502429/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/archive/1/515055/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/34256 | vdb-entryx_refsource_BIDPatchThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/usn-750-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.vmware.com/security/advisories/VMSA-2010-0019.html | x_refsource_CONFIRMThird Party Advisory | |
| http://www.vupen.com/english/advisories/2009/0850 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2009/1020 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2009/1175 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2009/1220 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2009/1548 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2010/0528 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2010/3126 | vdb-entryx_refsource_VUPENPermissions Required | |
| https://access.redhat.com/security/cve/CVE-2009-0590 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=492304 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/49431 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://kb.bluecoat.com/index?page=content&id=SA50 | x_refsource_CONFIRMThird Party Advisory | |
| https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html | mailing-listx_refsource_MLISTThird Party Advisory | |
| https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html | mailing-listx_refsource_MLISTThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-0590 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10198 | vdb-entrysignaturex_refsource_OVALThird Party Advisory | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6996 | vdb-entrysignaturex_refsource_OVALThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2009-0590 |
Change history (0)
No recorded changes yet.