CVE-2009-1377
CVE-2009-1377
The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=18187http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://marc.info/?l=openssl-dev&m=124247675613888&w=2http://rt.openssl.org/Ticket/Display.html?id=1930&user=guest&pass=guesthttp://secunia.com/advisories/35128http://secunia.com/advisories/35416http://secunia.com/advisories/35461http://secunia.com/advisories/35571http://secunia.com/advisories/35729