PT-2009-1100 · Openssl+1 · Openssl+1

Jon Oberheide

·

Publicado

2009-05-19

·

Atualizado

2024-06-15

·

CVE-2009-1378

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8k and earlier 0.9.8 versions
Description The issue is related to multiple memory leaks in the dtls1 process out of seq message function in ssl/d1 both.c. Remote attackers can cause a denial of service (memory consumption) via DTLS records that are duplicates or have sequence numbers much greater than current sequence numbers.
Recommendations For OpenSSL versions 0.9.8k and earlier 0.9.8 versions, update to a version later than 0.9.8k to resolve the issue. As a temporary workaround, consider restricting the handling of DTLS records to minimize the risk of exploitation.

Exploit

Correção

DoS

Improper Certificate Validation

Memory Leak

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09404
CVE-2009-1378
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2009:1335
RHSA-2009_1335
SUSE-FU-2022:0445-1

Produtos afetados

Openssl
Red Hat