CVE-2009-1378: Medium severity OpenSSL OpenSSL vulnerability
Multiple memory leaks in the dtls1processoutofseqmessage function in ssl/d1both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1378?
The severity of CVE-2009-1378 is categorized as high due to its potential to cause a denial of service.
How do I fix CVE-2009-1378?
To fix CVE-2009-1378, you should upgrade to a version of OpenSSL later than 0.9.8m.
What software is affected by CVE-2009-1378?
CVE-2009-1378 affects multiple versions of OpenSSL including all versions up to 0.9.8m.
What type of attack is associated with CVE-2009-1378?
CVE-2009-1378 is associated with denial of service attacks through memory leaks.
Can CVE-2009-1378 be exploited remotely?
Yes, CVE-2009-1378 can be exploited remotely by attackers sending specially crafted DTLS records.