Back

MEDIUM

openssl: DTLS memory leak from zero-length fragments

Published Aug 13, 2014

Description

Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via zero-length DTLS fragments that trigger improper handling of the return value of a certain insert function.

Affected products

Remediation

Red Hat statement

This did not affect openssl packages in Red Hat Enterprise Linux 5 (based on upstream 0.9.8e) and openssl 1.0.0 packages in Red Hat Enterprise Linux 6 (i.e. packages released before RHBA-2013:1585, which rebased openssl from 1.0.0 to 1.0.1e). The issue was introduced upstream in versions 0.9.8o and 1.0.0a.

Metrics

Weaknesses (2)

References (53)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 13, 2014
Updated Aug 6, 2024
Reserved May 14, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 6, 2014