mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 14:58:06 +02:00
848 B
848 B
CVE-2009-1386
Description
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
POC
Reference
- http://www.ubuntu.com/usn/USN-792-1
- http://www.ubuntu.com/usn/USN-792-1
- https://www.exploit-db.com/exploits/8873
- https://www.exploit-db.com/exploits/8873