Описание
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 0.9.8a-7ubuntu0.13 |
devel | released | 0.9.8k-7ubuntu8 |
hardy | released | 0.9.8g-4ubuntu3.11 |
intrepid | ignored | end of life, was needed |
jaunty | released | 0.9.8g-15ubuntu3.6 |
karmic | released | 0.9.8g-16ubuntu3.3 |
lucid | released | 0.9.8k-7ubuntu8 |
upstream | released | 0.9.8m |
Показывать по
EPSS
10 Critical
CVSS2
Связанные уязвимости
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
OpenSSL before 0.9.8m does not check for a NULL return value from bn_w ...
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Уязвимость операционной системы CentOS, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
10 Critical
CVSS2