Red Hat Bugzilla – Bug 494868
Invalid ASN1 clearing check vulnerability - (CVE-2009-0789)
Last modified: 2009-04-08 09:47:31 EDT
When a malformed ASN1 structure is received, it's contents are freed up and zeroed and an error condition returned. On a small number of platforms where sizeof(long) < sizeof(void *) (for example WIN64) this can cause an invalid memory access later resulting in a crash when some invalid structures are read, for example RSA public keys ). Any OpenSSL application which uses the public key of an untrusted certificate could be crashed by a malformed structure. Including SSL servers, clients, CA and S/MIME software.
Red Hat Enterprise Linux 4 (and any other version) does not support any platform where sizeof(long) < sizeof(void *).