CVE-2009-3245

UnknownEPSS 6.73%

Last modified

CVE-2009-3245 is a vulnerability of currently unknown severity. OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.. EPSS estimates a 6.73% chance of exploitation in the next 30 days.

Description

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

Metrics

EPSS Probability
6.73%

93.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpensslOpenssl<= 0.9.8l
OpensslOpenssl0.9.8
OpensslOpenssl0.9.8a
OpensslOpenssl0.9.8b
OpensslOpenssl0.9.8c
OpensslOpenssl0.9.8d
OpensslOpenssl0.9.8e
OpensslOpenssl0.9.8f
OpensslOpenssl0.9.8g
OpensslOpenssl0.9.8h
OpensslOpenssl0.9.8i
OpensslOpenssl0.9.8j
OpensslOpenssl0.9.8k

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-3245?
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
How severe is CVE-2009-3245?
Severity scoring for CVE-2009-3245 is pending analysis. The EPSS model estimates a 6.73% probability of exploitation in the next 30 days.
How do I fix CVE-2009-3245?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-3245?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST