LWN.net Logo

openssl: denial of service

Package(s):openssl CVE #(s):CVE-2009-4355
Created:January 14, 2010 Updated:April 19, 2010
Description: From the Debian alert:

It was discovered that a significant memory leak could occur in openssl, related to the reinitialization of zlib. This could result in a remotely exploitable denial of service vulnerability when using the Apache httpd server in a configuration where mod_ssl, mod_php5, and the php5-curl extension are loaded.

Alerts:
Gentoo 201110-01 2011-10-09
Fedora FEDORA-2010-5357 2010-03-26
Mandriva MDVSA-2010:022 2010-01-21
CentOS CESA-2010:0054 2010-01-20
Slackware SSA:2010-060-02 2010-03-02
Red Hat RHSA-2010:0054-01 2010-01-19
rPath rPSA-2010-0004-1 2010-01-14
Ubuntu USN-884-1 2010-01-14
Debian DSA-1970-1 2010-01-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds