CVE-2009-1386
published 2009-06-04CVE-2009-1386: ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS…
PriorityP342medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
80.13%
99.6th percentile
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | openssl | < openssl 0.9.8k-1 (bookworm) | openssl 0.9.8k-1 (bookworm) |
| openssl | openssl | < 0.9.8i | 0.9.8i |
| openssl | openssl | >= 0 < 0.9.8k-1 | 0.9.8k-1 |
| openssl | openssl | >= 0 < 0.9.8k-1 | 0.9.8k-1 |
| openssl | openssl | >= 0 < 0.9.8k-1 | 0.9.8k-1 |
| openssl | openssl | >= 0 < 0.9.8k-1 | 0.9.8k-1 |
| redhat | openssl | — | — |
| redhat | openssl | — | — |
| redhat | openssl | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x14\xfe\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x01
- →A single 14-byte UDP/DTLS datagram with content type 0x14 (ChangeCipherSpec) sent before any ClientHello triggers the crash. The malicious datagram is exactly 14 bytes and begins with the byte sequence \x14\xfe\xff (DTLS record type 20, version DTLS 1.0). ↗
- →Attack is delivered over UDP (SOCK_DGRAM). Monitor for DTLS ChangeCipherSpec records (record type 0x14) arriving on DTLS listener ports before any ClientHello handshake message from the same source. ↗
- →The Metasploit auxiliary module auxiliary/dos/ssl/dtls_changecipherspec can be used to reproduce and detect vulnerable DTLS endpoints. ↗
- ·The vulnerability only affects OpenSSL DTLS server implementations. No shipped Red Hat Enterprise Linux 5 component used OpenSSL's DTLS implementation in production; only the openssl CLI test client was affected. ↗
- ·Red Hat Enterprise Linux 3 and 4 are not affected; only RHEL 5 (openssl 0.9.8g) is vulnerable. ↗
- ·The crash is triggered only when the DTLS server receives a ChangeCipherSpec before its session structures are initialized (i.e., before ClientHello). Servers that never expose DTLS are not affected. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat6.8MEDIUM
vendor_debian5.0LOW
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: usb: buffer overflow in auerswald_probe()
vendor_redhat·2009-10-29·CVSS 6.8
CVE-2009-4067 [MEDIUM] kernel: usb: buffer overflow in auerswald_probe()
kernel: usb: buffer overflow in auerswald_probe()
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as the affected code has been removed. It was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included i
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2009-06-25·CVSS 5.0
CVE-2009-1377 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL vulnerabilities
It was discovered that OpenSSL did not limit the number of DTLS records it
would buffer when they arrived with a future epoch. A remote attacker could
cause a denial of service via memory resource consumption by sending a
large number of crafted requests. (CVE-2009-1377)
It was discovered that OpenSSL did not properly free memory when processing
DTLS fragments. A remote attacker could cause a denial of service via
memory resource consumption by sending a large number of crafted requests.
(CVE-2009-1378)
It was discovered that OpenSSL did not properly handle certain server
certificates when processing DTLS packets. A remote DTLS server could cause
a denial of service by sending a message containing a specially crafted
serve
Red Hat
openssl: DTLS NULL deref crash on early ChangeCipherSpec request
vendor_redhat·2009-06-02·CVSS 5.0
CVE-2009-1386 [MEDIUM] CWE-476 openssl: DTLS NULL deref crash on early ChangeCipherSpec request
openssl: DTLS NULL deref crash on early ChangeCipherSpec request
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
Debian
CVE-2009-1386: openssl - ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial ...
vendor_debian·2009·CVSS 5.0
CVE-2009-1386 [MEDIUM] CVE-2009-1386: openssl - ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial ...
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
Scope: local
bookworm: resolved (fixed in 0.9.8k-1)
bullseye: resolved (fixed in 0.9.8k-1)
forky: resolved (fixed in 0.9.8k-1)
sid: resolved (fixed in 0.9.8k-1)
trixie: resolved (fixed in 0.9.8k-1)
GHSA
GHSA-rqjx-gxhp-5x5r: ssl/s3_pkt
ghsa_unreviewed·2022-05-03
CVE-2009-1386 [MEDIUM] CWE-476 GHSA-rqjx-gxhp-5x5r: ssl/s3_pkt
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
OSV
CVE-2009-1386: ssl/s3_pkt
osv·2009-06-04·CVSS 5.0
CVE-2009-1386 [MEDIUM] CVE-2009-1386: ssl/s3_pkt
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
No detection rules found.
Exploit-DB
OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
exploitdb·2009-06-04·CVSS 5.0
CVE-2009-1386 [MEDIUM] OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
OpenSSL
* http://jon.oberheide.org
*
* Information:
*
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386
*
* OpenSSL would SegFault if the DTLS server receives a ChangeCipherSpec as
* the first record instead of ClientHello.
*
* Usage:
*
* Pass the host and port of the target DTLS server:
*
* $ gcc cve-2009-1386.c -o cve-2009-1386
* $ ./cve-2009-1386 1.2.3.4 666
*
* Notes:
*
* Much easier than the memory exhaustion DoS issue (CVE-2009-1378) as this
* only requires a single ChangeCipherSpec datagram, but affects an older
* version of OpenSSL.
*
*/
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
int
main(int argc, char **argv)
{
int sock, ret;
char *ptr, *err;
struct hostent *h;
struct sockaddr_in target;
char buf[64];
if (argc h_addrty
Metasploit
OpenSSL DTLS ChangeCipherSpec Remote DoS
metasploit
OpenSSL DTLS ChangeCipherSpec Remote DoS
OpenSSL DTLS ChangeCipherSpec Remote DoS
This module performs a Denial of Service Attack against Datagram TLS in OpenSSL version 0.9.8i and earlier. OpenSSL crashes under these versions when it receives a ChangeCipherspec Datagram before a ClientHello.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=17369http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://rt.openssl.org/Ticket/Display.html?id=1679&user=guest&pass=guesthttp://secunia.com/advisories/35571http://secunia.com/advisories/35685http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://www.openwall.com/lists/oss-security/2009/06/02/1http://www.redhat.com/support/errata/RHSA-2009-1335.htmlhttp://www.securityfocus.com/bid/35174http://www.ubuntu.com/usn/USN-792-1http://www.vupen.com/english/advisories/2010/0528https://exchange.xforce.ibmcloud.com/vulnerabilities/50963https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11179https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7469https://www.exploit-db.com/exploits/8873ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=17369http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://rt.openssl.org/Ticket/Display.html?id=1679&user=guest&pass=guesthttp://secunia.com/advisories/35571http://secunia.com/advisories/35685http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://www.openwall.com/lists/oss-security/2009/06/02/1http://www.redhat.com/support/errata/RHSA-2009-1335.htmlhttp://www.securityfocus.com/bid/35174http://www.ubuntu.com/usn/USN-792-1http://www.vupen.com/english/advisories/2010/0528https://exchange.xforce.ibmcloud.com/vulnerabilities/50963https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11179https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7469https://www.exploit-db.com/exploits/8873
2009-06-04
Published