CVE-2009-1377: Buffer Overflow
Published May 19, 2009
·Updated
The dtls1bufferrecord function in ssl/d1pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
Affected Software
22 affected components
OpenSSL OpenSSL>=0.9.8<0.9.8m
OpenSSL OpenSSL=0.9.8b
OpenSSL OpenSSL=0.9.8c
OpenSSL OpenSSL=0.9.8e
OpenSSL OpenSSL=0.9.8g
OpenSSL OpenSSL=0.9.8k
OpenSSL OpenSSL=0.9.8d
OpenSSL OpenSSL=0.9.8j
OpenSSL OpenSSL=0.9.8a
OpenSSL OpenSSL=0.9.8i
OpenSSL OpenSSL=0.9.8f
OpenSSL OpenSSL=0.9.8h
OpenSSL OpenSSL<0.9.8
OpenSSL OpenSSL=0.9.8
OpenSSL OpenSSL=0.9.8-beta1
OpenSSL OpenSSL=0.9.8-beta2
OpenSSL OpenSSL=0.9.8-beta3
OpenSSL OpenSSL=0.9.8-beta4
OpenSSL OpenSSL=0.9.8-beta5
OpenSSL OpenSSL=0.9.8-beta6
OpenSSL OpenSSL=0.9.8c-1
OpenSSL OpenSSL=0.9.8g-9
Remediation
Patch Available
Patch Available
Event History
May 19, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Feb 17, 2026
Data Sourced
via Launchpad·07:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1377?
CVE-2009-1377 has a severity level that can lead to a denial of service due to memory consumption.
2
How do I fix CVE-2009-1377?
To fix CVE-2009-1377, you should upgrade to a later version of OpenSSL beyond 0.9.8m.
3
What software versions are affected by CVE-2009-1377?
CVE-2009-1377 affects OpenSSL versions 0.9.8k and earlier, including earlier 0.9.8 versions.
4
Is CVE-2009-1377 a remote attack vulnerability?
Yes, CVE-2009-1377 can be exploited by remote attackers through a large series of DTLS records.
5
What are the implications of exploiting CVE-2009-1377?
Exploiting CVE-2009-1377 can lead to a denial of service through excessive memory consumption.