ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 0.9.8 (excluding) | 0.9.8i (excluding) |
Openssl | Ubuntu | dapper | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | hardy | * |
Openssl | Ubuntu | intrepid | * |
Openssl | Ubuntu | jaunty | * |
Openssl | Ubuntu | upstream | * |
Red Hat Enterprise Linux 5 | RedHat | openssl-0:0.9.8e-12.el5 | * |