CVE-2009-4355
published 2010-01-14CVE-2009-4355: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.94%
94.7th percentile
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8k-8 (bookworm) | openssl 0.9.8k-8 (bookworm) |
| openssl | openssl | <= 0.9.8l | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2010-01-14
CVE-2009-4355 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL vulnerability
It was discovered that OpenSSL did not correctly free unused memory in
certain situations. A remote attacker could trigger this flaw in services
that used SSL, causing the service to use all available system memory,
leading to a denial of service.
Instructions: After a standard system upgrade you need to restart any applications
using OpenSSL, especially Apache, to effect the necessary changes.
Red Hat
openssl significant memory leak in certain SSLv3 requests (DoS)
vendor_redhat·2010-01-13·CVSS 5.0
CVE-2009-4355 [MEDIUM] CWE-401 openssl significant memory leak in certain SSLv3 requests (DoS)
openssl significant memory leak in certain SSLv3 requests (DoS)
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Debian
CVE-2009-4355: openssl - Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in Open...
vendor_debian·2009·CVSS 5.0
CVE-2009-4355 [MEDIUM] CVE-2009-4355: openssl - Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in Open...
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Scope: local
bookworm: resolved (fixed in 0.9.8k-8)
bullseye: resolved (fixed in 0.9.8k-8)
forky: resolved (fixed in 0.9.8k-8)
sid: resolved (fixed in 0.9.8k-8)
trixie: resolved (fixed in 0.9.8k-8)
GHSA
GHSA-cg3r-vf2p-3f9h: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-4355 [MEDIUM] GHSA-cg3r-vf2p-3f9h: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
OSV
CVE-2009-4355: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
osv·2010-01-14·CVSS 5.0
CVE-2009-4355 [MEDIUM] CVE-2009-4355: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
No detection rules found.
No public exploits indexed.
http://cvs.openssl.org/chngview?cn=19068http://cvs.openssl.org/chngview?cn=19069http://cvs.openssl.org/chngview?cn=19167http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://marc.info/?l=bugtraq&m=127128920008563&w=2http://secunia.com/advisories/38175http://secunia.com/advisories/38181http://secunia.com/advisories/38200http://secunia.com/advisories/38761http://secunia.com/advisories/39461http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0004http://www.debian.org/security/2010/dsa-1970http://www.mandriva.com/security/advisories?name=MDVSA-2010:022http://www.openwall.com/lists/oss-security/2010/01/13/3http://www.ubuntu.com/usn/USN-884-1http://www.vupen.com/english/advisories/2010/0124http://www.vupen.com/english/advisories/2010/0839http://www.vupen.com/english/advisories/2010/0916https://bugzilla.redhat.com/show_bug.cgi?id=546707https://issues.rpath.com/browse/RPL-3157https://kb.bluecoat.com/index?page=content&id=SA50https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11260https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6678https://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://cvs.openssl.org/chngview?cn=19068http://cvs.openssl.org/chngview?cn=19069http://cvs.openssl.org/chngview?cn=19167http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://marc.info/?l=bugtraq&m=127128920008563&w=2http://secunia.com/advisories/38175http://secunia.com/advisories/38181http://secunia.com/advisories/38200http://secunia.com/advisories/38761http://secunia.com/advisories/39461http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0004http://www.debian.org/security/2010/dsa-1970http://www.mandriva.com/security/advisories?name=MDVSA-2010:022http://www.openwall.com/lists/oss-security/2010/01/13/3http://www.ubuntu.com/usn/USN-884-1http://www.vupen.com/english/advisories/2010/0124http://www.vupen.com/english/advisories/2010/0839http://www.vupen.com/english/advisories/2010/0916https://bugzilla.redhat.com/show_bug.cgi?id=546707https://issues.rpath.com/browse/RPL-3157https://kb.bluecoat.com/index?page=content&id=SA50https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11260https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6678https://rhn.redhat.com/errata/RHSA-2010-0095.html
2010-01-14
Published