CVE-2009-1379

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
19/05/2009
Last modified:
09/04/2025

Description

Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools