CVE-2009-1386
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 80%
from disclosure to weapon0 days
Published on NVDJun 4
metasploitApr 26
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/8873⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=17369http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://rt.openssl.org/Ticket/Display.html?id=1679&user=guest&pass=guesthttp://secunia.com/advisories/35571http://secunia.com/advisories/35685http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/38794http://secunia.com/advisories/38834