PT-2009-1100 · Openssl+1 · Openssl+1
Jon Oberheide
·
Publicado
2009-05-19
·
Atualizado
2024-06-15
·
CVE-2009-1378
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 0.9.8k and earlier 0.9.8 versions
Description
The issue is related to multiple memory leaks in the dtls1 process out of seq message function in ssl/d1 both.c. Remote attackers can cause a denial of service (memory consumption) via DTLS records that are duplicates or have sequence numbers much greater than current sequence numbers.
Recommendations
For OpenSSL versions 0.9.8k and earlier 0.9.8 versions, update to a version later than 0.9.8k to resolve the issue. As a temporary workaround, consider restricting the handling of DTLS records to minimize the risk of exploitation.
Exploit
Correção
DoS
Improper Certificate Validation
Memory Leak
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openssl
Red Hat