PT-2009-1102 · Openssl+1 · Openssl+1

Tomas Hoger

·

Published

2009-02-05

·

Updated

2024-06-15

·

CVE-2009-1387

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0 Beta 2 OpenSSL versions prior to 0.9.8l-r2
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash due to a NULL pointer dereference. This is related to an out-of-sequence DTLS handshake message and a "fragment bug" in the dtls1 retrieve buffered fragment function. The vulnerability can be exploited remotely, potentially leading to disruption of integrity and availability of protected information.
Recommendations For versions prior to 1.0.0 Beta 2, update to version 1.0.0 Beta 2 or later. For versions prior to 0.9.8l-r2, update to version 0.9.8l-r2 or later. As a temporary workaround, consider restricting access to DTLS handshake messages to minimize the risk of exploitation.

Fix

DoS

Improper Certificate Validation

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09404
CVE-2009-1387
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2009:1335
RHSA-2009_1335
SUSE-FU-2022:0445-1

Affected Products

Openssl
Red Hat