Vulnerability Description
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | <= 0.9.8l |
| Redhat | Openssl | 0.9.6-15 |
Related Weaknesses (CWE)
References
- http://cvs.openssl.org/chngview?cn=19068
- http://cvs.openssl.org/chngview?cn=19069
- http://cvs.openssl.org/chngview?cn=19167
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
- http://marc.info/?l=bugtraq&m=127128920008563&w=2
- http://secunia.com/advisories/38175Vendor Advisory
- http://secunia.com/advisories/38181Vendor Advisory
- http://secunia.com/advisories/38200Vendor Advisory
- http://secunia.com/advisories/38761
- http://secunia.com/advisories/39461
- http://secunia.com/advisories/42724
- http://secunia.com/advisories/42733
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware
FAQ
What is CVE-2009-4355?
CVE-2009-4355 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consum...
How severe is CVE-2009-4355?
CVE-2009-4355 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4355?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Redhat Openssl.