CVE Reference: CVE-2009-1387

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2009-1387

Description:
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/USN-792-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html

SAID
  Secunia Advisory: SA35571
  Secunia Advisory: SA35685
  Secunia Advisory: SA35729
  Secunia Advisory: SA37003
  Secunia Advisory: SA38794
  Secunia Advisory: SA38834
  Secunia Advisory: SA36533

REDHAT
  http://www.redhat.com/support/errata/RHSA-2009-1335.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10740
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7592

NETBSD

MLIST
  http://lists.vmware.com/pipermail/security-announce/2010/000082.html
  http://www.openwall.com/lists/oss-security/2009/06/02/1

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444

GENTOO
  http://security.gentoo.org/glsa/glsa-200912-01.xml

CONFIRM
  http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html
  http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net
  http://rt.openssl.org/Ticket/Display.html?id=1838&user=guest&pass=guest
  http://cvs.openssl.org/chngview?cn=17958


Return to the previous page.