PT-2009-1100 · Openssl+1 · Openssl+1
Jon Oberheide
·
Published
2009-05-19
·
Updated
2024-06-15
·
CVE-2009-1378
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 0.9.8k and earlier 0.9.8 versions
Description
The issue is related to multiple memory leaks in the dtls1 process out of seq message function in ssl/d1 both.c. Remote attackers can cause a denial of service (memory consumption) via DTLS records that are duplicates or have sequence numbers much greater than current sequence numbers.
Recommendations
For OpenSSL versions 0.9.8k and earlier 0.9.8 versions, update to a version later than 0.9.8k to resolve the issue. As a temporary workaround, consider restricting the handling of DTLS records to minimize the risk of exploitation.
Exploit
Fix
DoS
Improper Certificate Validation
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Red Hat