5

CVE-2009-1386

Exploit

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version > 0.9.8 < 0.9.8i
RedhatOpenSSL Version0.9.6-15
RedhatOpenSSL Version0.9.6b-3
RedhatOpenSSL Version0.9.7a-2
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 42.63% 0.974
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://secunia.com/advisories/38794
Third Party Advisory
Not Applicable
http://www.vupen.com/english/advisories/2010/0528
Third Party Advisory
Permissions Required
http://secunia.com/advisories/35685
Third Party Advisory
Not Applicable
http://secunia.com/advisories/35729
Third Party Advisory
Not Applicable
http://secunia.com/advisories/36533
Third Party Advisory
Not Applicable
http://secunia.com/advisories/35571
Third Party Advisory
Not Applicable
http://cvs.openssl.org/chngview?cn=17369
Patch
Third Party Advisory
Broken Link
http://www.securityfocus.com/bid/35174
Third Party Advisory
Exploit
Broken Link
VDB Entry
https://www.exploit-db.com/exploits/8873
Third Party Advisory
Exploit
VDB Entry