CVE-2009-1378
Summary
Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
Impact & exploitability
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://cvs.openssl.org/chngview?cn=18188 ↗
Additional information
- NVD record
- http://cvs.openssl.org/chngview?cn=18188Patch
- http://marc.info/?l=openssl-dev&m=124247679213944&w=2Patch
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.ascAdvisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlAdvisory
- http://lists.vmware.com/pipermail/security-announce/2010/000082.htmlAdvisory
- http://rt.openssl.org/Ticket/Display.html?id=1931&user=guest&pass=guestAdvisory
- http://marc.info/?l=openssl-dev&m=124263491424212&w=2Advisory