Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1377

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.035
EPSS Ranking 87.2%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2009-1377
  • Openssl » Openssl » Version: 0.9.8
    cpe:2.3:a:openssl:openssl:0.9.8
  • Openssl » Openssl » Version: 0.9.8a
    cpe:2.3:a:openssl:openssl:0.9.8a
  • Openssl » Openssl » Version: 0.9.8b
    cpe:2.3:a:openssl:openssl:0.9.8b
  • Openssl » Openssl » Version: 0.9.8c
    cpe:2.3:a:openssl:openssl:0.9.8c
  • Openssl » Openssl » Version: 0.9.8c-1
    cpe:2.3:a:openssl:openssl:0.9.8c-1
  • Openssl » Openssl » Version: 0.9.8d
    cpe:2.3:a:openssl:openssl:0.9.8d
  • Openssl » Openssl » Version: 0.9.8e
    cpe:2.3:a:openssl:openssl:0.9.8e
  • Openssl » Openssl » Version: 0.9.8f
    cpe:2.3:a:openssl:openssl:0.9.8f
  • Openssl » Openssl » Version: 0.9.8g
    cpe:2.3:a:openssl:openssl:0.9.8g
  • Openssl » Openssl » Version: 0.9.8g-9
    cpe:2.3:a:openssl:openssl:0.9.8g-9
  • Openssl » Openssl » Version: 0.9.8h
    cpe:2.3:a:openssl:openssl:0.9.8h
  • Openssl » Openssl » Version: 0.9.8i
    cpe:2.3:a:openssl:openssl:0.9.8i
  • Openssl » Openssl » Version: 0.9.8j
    cpe:2.3:a:openssl:openssl:0.9.8j
  • Openssl » Openssl » Version: 0.9.8k
    cpe:2.3:a:openssl:openssl:0.9.8k
  • Openssl » Openssl » Version: 0.9.8l
    cpe:2.3:a:openssl:openssl:0.9.8l


Contact Us

Shodan ® - All rights reserved