PT-2009-1102 · Openssl+1 · Openssl+1

Tomas Hoger

·

Publicado

2009-02-05

·

Atualizado

2024-06-15

·

CVE-2009-1387

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0 Beta 2 OpenSSL versions prior to 0.9.8l-r2
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This is related to an out-of-sequence DTLS handshake message and a "fragment bug" in the dtls1 retrieve buffered fragment function. The vulnerability can be exploited remotely, potentially leading to disruption of integrity and availability of protected information.
Recommendations For versions prior to 1.0.0 Beta 2, update to version 1.0.0 Beta 2 or later. For versions prior to 0.9.8l-r2, update to version 0.9.8l-r2 or later. As a temporary workaround, consider restricting access to DTLS handshake messages to minimize the risk of exploitation.

Correção

DoS

Improper Certificate Validation

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09404
CVE-2009-1387
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2009:1335
RHSA-2009_1335
SUSE-FU-2022:0445-1

Produtos afetados

Openssl
Red Hat