Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Openssl: Denial of Service
Posted by Benjamin D. Thomas
exploited by malicious people to cause a DoS (Denial of Service).
--==============74292285=Content-Type: multipart/alternative; boundary 1636c5a537913aa0046a8fe11c
--001636c5a537913aa0046a8fe11c
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-78 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-05-23
Severity: 2
Type: Remote
------------------------------------------------------------------------
Summary
======
Two vulnerabilities have been reported in OpenSSL, which can be
exploited by malicious people to cause a DoS (Denial of Service).
Description
==========
1) The library does not limit the number of buffered DTLS records with a
future epoch. This can be exploited to exhaust all available memory via
specially crafted DTLS packets.
2) An error when processing DTLS messages can be exploited to exhaust
all available memory by sending a large number of out of sequence
handshake messages.
Affected packages:
Pardus 2008:
openssl, all before 0.9.8k-21-8
Resolution
=========
There are update(s) for openssl. You can update them via Package Manager
or with a single command from console:
pisi up openssl
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id—78
* http://rt.openssl.org/Ticket/Display.html?id30
* http://rt.openssl.org/Ticket/Display.html?id31
* http://cvs.openssl.org/chngview?cn187
* http://cvs.openssl.org/chngview?cn188
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1377
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1378
* http://secunia.com/advisories/35128