oss-sec mailing list archives

Re: Two OpenSSL DTLS remote DoS


From: Mark J Cox <mjc () redhat com>
Date: Mon, 18 May 2009 19:50:54 +0100 (BST)

Stephen Henson pointed out that there is one other DTLS issue that probably has security consequences too, and that backporting DTLS issues is probably not the right thing to do given the amount of change happening in the DTLS code to fix protocol errors etc:

CVE-2009-1379 DTLS fragment read after free DoS
http://rt.openssl.org/Ticket/Display.html?id=1923&user=guest&pass=guest

Mark


Current thread: