Bug 494868 - Invalid ASN1 clearing check vulnerability - (CVE-2009-0789)
Invalid ASN1 clearing check vulnerability - (CVE-2009-0789)
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: openssl (Show other bugs)
x86_64 Linux
low Severity medium
: rc
: ---
Assigned To: Tomas Mraz
Depends On:
  Show dependency treegraph
Reported: 2009-04-08 09:32 EDT by George Deng
Modified: 2009-04-08 09:47 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2009-04-08 09:47:31 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description George Deng 2009-04-08 09:32:44 EDT
When a malformed ASN1 structure is received, it's contents are freed up and zeroed and an error condition returned. On a small number of platforms where sizeof(long) < sizeof(void *) (for example WIN64) this can cause an invalid memory access later resulting in a crash when some invalid structures are read, for example RSA public keys ). Any OpenSSL application which uses the public key of an untrusted certificate could be crashed by a malformed structure. Including SSL servers, clients, CA and S/MIME software.
Comment 1 Tomas Mraz 2009-04-08 09:47:31 EDT
Red Hat Enterprise Linux 4 (and any other version) does not support any platform where sizeof(long) < sizeof(void *).

Note You need to log in before you can comment on or make changes to this bug.