Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2009-05-19T19:00:00
Updated: 2024-08-07T05:13:25.511Z
Reserved: 2009-04-23T00:00:00
Link: CVE-2009-1378
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-05-19T19:30:00.750
Modified: 2024-11-21T01:02:20.483
Link: CVE-2009-1378
Redhat