cbcvebase.
CVE-2015-0206
published 2015-01-09

CVE-2015-0206: Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of…

PriorityP336medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
59.32%
99.0th percentile
Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoproducts
debianopenssl< openssl 1.0.1k-1 (bookworm)openssl 1.0.1k-1 (bookworm)
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector: attacker sends many duplicate DTLS records with the same sequence number but for the next epoch, triggering memory leak in dtls1_buffer_record() via failure of replay detection
  • Vulnerable function and source file: dtls1_buffer_record() in d1_pkt.c — monitor for memory exhaustion on DTLS-speaking services running OpenSSL 1.0.0 before 1.0.0p or 1.0.1 before 1.0.1k
  • Upstream fix commit for reference in patch-level detection: https://github.com/openssl/openssl/commit/103b171d8fc282ef435f8de9afbf7782e312961f
  • ·Vulnerability only affects OpenSSL 1.0.0 (before 1.0.0p) and 1.0.1 (before 1.0.1k); openssl097a, openssl098e, and RHEL 5 openssl are NOT affected
  • ·Attack is only possible against DTLS servers; the attacker must be able to send DTLS traffic to the target service

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_cisco5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.