CVE-2009-1387
published 2009-06-04CVE-2009-1387: The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
10.25%
95.2th percentile
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | openssl | < openssl 0.9.8k-2 (bookworm) | openssl 0.9.8k-2 (bookworm) |
| openssl | openssl | >= 0 < 0.9.8k-2 | 0.9.8k-2 |
| openssl | openssl | >= 0 < 0.9.8k-2 | 0.9.8k-2 |
| openssl | openssl | >= 0 < 0.9.8k-2 | 0.9.8k-2 |
| openssl | openssl | >= 0 < 0.9.8k-2 | 0.9.8k-2 |
| openssl | openssl | >= 0.9.8 < 0.9.8m | 0.9.8m |
| redhat | openssl | — | — |
| redhat | openssl | — | — |
| redhat | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2009-06-25·CVSS 5.0
CVE-2009-1377 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL vulnerabilities
It was discovered that OpenSSL did not limit the number of DTLS records it
would buffer when they arrived with a future epoch. A remote attacker could
cause a denial of service via memory resource consumption by sending a
large number of crafted requests. (CVE-2009-1377)
It was discovered that OpenSSL did not properly free memory when processing
DTLS fragments. A remote attacker could cause a denial of service via
memory resource consumption by sending a large number of crafted requests.
(CVE-2009-1378)
It was discovered that OpenSSL did not properly handle certain server
certificates when processing DTLS packets. A remote DTLS server could cause
a denial of service by sending a message containing a specially crafted
serve
Red Hat
openssl: DTLS out-of-sequence message handling NULL deref DoS
vendor_redhat·2009-06-02·CVSS 5.0
CVE-2009-1387 [MEDIUM] CWE-476 openssl: DTLS out-of-sequence message handling NULL deref DoS
openssl: DTLS out-of-sequence message handling NULL deref DoS
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
Debian
CVE-2009-1387: openssl - The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before...
vendor_debian·2009·CVSS 5.0
CVE-2009-1387 [MEDIUM] CVE-2009-1387: openssl - The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before...
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
Scope: local
bookworm: resolved (fixed in 0.9.8k-2)
bullseye: resolved (fixed in 0.9.8k-2)
forky: resolved (fixed in 0.9.8k-2)
sid: resolved (fixed in 0.9.8k-2)
trixie: resolved (fixed in 0.9.8k-2)
GHSA
GHSA-rf8c-7g59-3m3m: The dtls1_retrieve_buffered_fragment function in ssl/d1_both
ghsa_unreviewed·2022-05-03
CVE-2009-1387 [MEDIUM] CWE-476 GHSA-rf8c-7g59-3m3m: The dtls1_retrieve_buffered_fragment function in ssl/d1_both
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
OSV
CVE-2009-1387: The dtls1_retrieve_buffered_fragment function in ssl/d1_both
osv·2009-06-04·CVSS 5.0
CVE-2009-1387 [MEDIUM] CVE-2009-1387: The dtls1_retrieve_buffered_fragment function in ssl/d1_both
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
No detection rules found.
No public exploits indexed.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=17958http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://rt.openssl.org/Ticket/Display.html?id=1838&user=guest&pass=guesthttp://secunia.com/advisories/35571http://secunia.com/advisories/35685http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/37003http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://security.gentoo.org/glsa/glsa-200912-01.xmlhttp://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.nethttp://voodoo-circle.sourceforge.net/sa/sa-20091012-01.htmlhttp://www.openwall.com/lists/oss-security/2009/06/02/1http://www.redhat.com/support/errata/RHSA-2009-1335.htmlhttp://www.ubuntu.com/usn/USN-792-1http://www.vupen.com/english/advisories/2010/0528https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10740https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7592ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.aschttp://cvs.openssl.org/chngview?cn=17958http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://rt.openssl.org/Ticket/Display.html?id=1838&user=guest&pass=guesthttp://secunia.com/advisories/35571http://secunia.com/advisories/35685http://secunia.com/advisories/35729http://secunia.com/advisories/36533http://secunia.com/advisories/37003http://secunia.com/advisories/38794http://secunia.com/advisories/38834http://security.gentoo.org/glsa/glsa-200912-01.xmlhttp://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.nethttp://voodoo-circle.sourceforge.net/sa/sa-20091012-01.htmlhttp://www.openwall.com/lists/oss-security/2009/06/02/1http://www.redhat.com/support/errata/RHSA-2009-1335.htmlhttp://www.ubuntu.com/usn/USN-792-1http://www.vupen.com/english/advisories/2010/0528https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10740https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7592
2009-06-04
Published