Description
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Remediation
References
Related Vulnerabilities
Perl Out-of-bounds Write Vulnerability (CVE-2023-47038)
MySQL CVE-2020-14632 Vulnerability (CVE-2020-14632)
MediaWiki Insertion of Sensitive Information into Log File Vulnerability (CVE-2024-40596)
MediaWiki Improper Access Control Vulnerability (CVE-2012-4380)
Internet Information Services Other Vulnerability (CVE-2002-1181)