Vulnerability Description
The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 0.9.8, < 0.9.8m |
Related Weaknesses (CWE)
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.ascBroken LinkThird Party Advisory
- http://cvs.openssl.org/chngview?cn=18187Broken LinkPatchThird Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444Broken LinkThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2010/000082.htmlThird Party Advisory
- http://marc.info/?l=openssl-dev&m=124247675613888&w=2Mailing ListPatchThird Party Advisory
- http://rt.openssl.org/Ticket/Display.html?id=1930&user=guest&pass=guestBroken LinkMailing ListPatch
- http://secunia.com/advisories/35128Third Party AdvisoryVendor Advisory
- http://secunia.com/advisories/35416Third Party Advisory
- http://secunia.com/advisories/35461Third Party Advisory
- http://secunia.com/advisories/35571Third Party Advisory
- http://secunia.com/advisories/35729Third Party Advisory
- http://secunia.com/advisories/36533Third Party Advisory
- http://secunia.com/advisories/37003Third Party Advisory
- http://secunia.com/advisories/38761Third Party Advisory
FAQ
What is CVE-2009-1377?
CVE-2009-1377 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future ep...
How severe is CVE-2009-1377?
CVE-2009-1377 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1377?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl.