CVE-2014-9424: Double Free
Double free vulnerability in the sslparseclienthellousesrtpext function in d1srtp.c in LibreSSL before 2.1.2 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a certain length-verification error during processing of a DTLS handshake.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9424?
CVE-2014-9424 has a severity rating that can lead to denial of service and potential unspecified impacts.
How do I fix CVE-2014-9424?
To fix CVE-2014-9424, upgrade LibreSSL to version 2.1.2 or later.
What versions of LibreSSL are affected by CVE-2014-9424?
LibreSSL versions prior to 2.1.2 are affected by CVE-2014-9424.
How can CVE-2014-9424 be exploited?
CVE-2014-9424 can be exploited by remote attackers through a specially crafted DTLS handshake triggering a length-verification error.
What impact does CVE-2014-9424 have on my system?
The impact of CVE-2014-9424 includes potential denial of service and possible other unspecified impacts on system security.