OpenSSL: DTLS pointer use-after-free flaw (DoS)
Published May 19, 2009
5.0
MEDIUMCVSS 2.0
EPSS 18.24%
Description
Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.
Affected products
Remediation
Red Hat statement
This issue did not affect versions of openssl as shipped in Red Hat Enterprise Linux 3 and 4. Note that both the DTLS specification and OpenSSLs implementation is still in development and unlikely to be used in production environments. There is no component shipped in Red Hat Enterprise Linux 5 using OpenSSLs DTLS implementation, except for OpenSSLs testing command line client - openssl.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 18.24% (0.18241) | 97.14th | v5 (v2026.06.15) |
| Jun 15, 2026 | 18.24% (0.18241) | 96.84th | v5 (v2026.06.15) |
| Dec 28, 2025 | 8.56% (0.08556) | 92.10th | v4 (v2025.03.14) |
| Dec 27, 2025 | 10.53% (0.10528) | 93.05th | v4 (v2025.03.14) |
| Oct 28, 2025 | 8.30% (0.08305) | 91.86th | v4 (v2025.03.14) |
| Oct 27, 2025 | 10.23% (0.10227) | 92.82th | v4 (v2025.03.14) |
| Oct 1, 2025 | 8.80% (0.08800) | 92.22th | v4 (v2025.03.14) |
| Jul 30, 2025 | 10.23% (0.10227) | 92.81th | v4 (v2025.03.14) |
| Jul 16, 2025 | 8.30% (0.08305) | 91.84th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.50% (0.06505) | 90.19th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.31% (0.09313) | 87.80th | v4 (v2025.03.14) |
| Mar 25, 2025 | 7.18% (0.07182) | 90.67th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.56% (0.05565) | 89.59th | v4 (v2025.03.14) |
| Dec 12, 2024 | 11.73% (0.11735) | 95.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 11.73% (0.11735) | 94.36th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Feb 13, 2023 | 7.56% (0.07559) | 92.57th | v2 (v2022.01.01) |
| Feb 3, 2023 | 4.72% (0.04720) | 88.89th | v2 (v2022.01.01) |
| Jul 18, 2022 | 7.56% (0.07559) | 92.47th | v2 (v2022.01.01) |
| Jul 17, 2022 | 4.36% (0.04358) | 87.36th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
References (36)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc vendor-advisoryx_refsource_NETBSD
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444 vendor-advisoryx_refsource_HP
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLIST
- http://rt.openssl.org/Ticket/Display.html?id=1923&user=guest&pass=guest x_refsource_CONFIRMExploit
- http://secunia.com/advisories/35416 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35461 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35571 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35729 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36533 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37003 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38761 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42724 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42733 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200912-01.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049 vendor-advisoryx_refsource_SLACKWARE
- http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net x_refsource_CONFIRM
- http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2009/05/18/4 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2009-1335.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/35138 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022241 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-792-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/1377 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-1379 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=501572 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50661 vdb-entryx_refsource_XF
- https://kb.bluecoat.com/index?page=content&id=SA50 x_refsource_CONFIRM
- https://launchpad.net/bugs/cve/2009-1379 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2009-1379
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6848 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9744 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-1379
Change history (0)
No recorded changes yet.