Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-1386

Опубликовано: 02 июн. 2009
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=503685openssl: DTLS NULL deref crash on early ChangeCipherSpec request

EPSS

Процентиль: 97%
0.42628
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

nvd
около 16 лет назад

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

debian
около 16 лет назад

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause ...

github
около 3 лет назад

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

oracle-oval
почти 16 лет назад

ELSA-2009-1335: openssl security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 97%
0.42628
Средний

5 Medium

CVSS2