Skip to main content

OpenSSL DTLS Denial of Service Vulnerability

Last Update Date: 20 Jan 2012 09:59 Release Date: 20 Jan 2012 5033 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in OpenSSL. A remote user can cause denial of service conditions.

 

The fix to correct the Datagram Transport Layer Security (DTLS) vulnerability referenced by CVE-2011-4108 (SA12010501) introduced a flaw. A remote user can send specially crafted data to cause denial of service conditions on the target system.


Impact

  • Denial of Service

System / Technologies affected

  • DTLS applications using OpenSSL 1.0.0f and 0.9.8s

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to OpenSSL 0.9.8t and 1.0.0g.

Vulnerability Identifier


Source


Related Link