|
|
Subscribe / Log in / New account

openssl: multiple vulnerabilities

Package(s):openssl CVE #(s):CVE-2009-1377 CVE-2009-1378
Created:May 21, 2009 Updated:March 2, 2010
Description: Openssl has two vulnerabilities, from the Mandriva alert:

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of future epoch DTLS records that are buffered in a queue, aka DTLS record buffer limitation bug. (CVE-2009-1377)

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka DTLS fragment handling memory leak. (CVE-2009-1378)

Alerts:
Slackware SSA:2010-060-02 openssl 2010-03-02
Mandriva MDVSA-2009:310 openssl 2009-12-03
Gentoo 200912-01 openssl 2009-12-01
Debian DSA-1888-1 openssl 2009-09-15
CentOS CESA-2009:1335 openssl 2009-09-15
Red Hat RHSA-2009:1335-02 openssl 2009-09-02
Ubuntu USN-792-1 openssl 2009-06-25
Fedora FEDORA-2009-5423 openssl 2009-05-25
Fedora FEDORA-2009-5412 openssl 2009-05-25
Fedora FEDORA-2009-5452 openssl 2009-05-25
SuSE SUSE-SR:2009:011 java, realplayer, acroread, apache2-mod_security2, cyrus-sasl, wireshark, ganglia-monitor-core, ghostscript-devel, libwmf, libxine1, net-snmp, ntp, openssl 2009-06-09
Mandriva MDVSA-2009:120 openssl 2009-05-21

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds