A AegiFlow
MEDIUMCVSS 5.0

CVE-2009-1378

CVE-2009-1378 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."

Affected packages

EcosystemPackageAffected versionsFixed versions
OpenSSLopenssl[object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.