vendor:
OpenSSL
by:
Jon Oberheide
7,8
CVSS
HIGH
Denial of Service
399
CWE
Product Name: OpenSSL
Affected Version From: OpenSSL < 0.9.8i
Affected Version To: OpenSSL < 0.9.8i
Patch Exists: YES
Related CWE: CVE-2009-1386
CPE: 2.6.39
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0009-1-service-console-package-openssl-cve-2009-1386/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-1386/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1335/, https://www.rapid7.com/db/vulnerabilities/http-openssl-changecipherspec-dtls-packet-dos/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-1386/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2009-1386/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
OpenSSL < 0.9.8i DTLS ChangeCipherSpec Remote DoS
OpenSSL would SegFault if the DTLS server receives a ChangeCipherSpec as the first record instead of ClientHello.
Mitigation:
Upgrade to OpenSSL 0.9.8i or later