PT-2009-1100 · Openssl+1 · Openssl+1

Jon Oberheide

·

Published

2009-05-19

·

Updated

2024-06-15

·

CVE-2009-1378

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8k and earlier 0.9.8 versions
Description The issue is related to multiple memory leaks in the dtls1 process out of seq message function in ssl/d1 both.c. Remote attackers can cause a denial of service (memory consumption) via DTLS records that are duplicates or have sequence numbers much greater than current sequence numbers.
Recommendations For OpenSSL versions 0.9.8k and earlier 0.9.8 versions, update to a version later than 0.9.8k to resolve the issue. As a temporary workaround, consider restricting the handling of DTLS records to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Certificate Validation

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09404
CVE-2009-1378
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2009:1335
RHSA-2009_1335
SUSE-FU-2022:0445-1

Affected Products

Openssl
Red Hat