OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 0.9.8s (including) | 0.9.8s (including) |
Openssl | Openssl | 1.0.0f (including) | 1.0.0f (including) |
Openssl | Ubuntu | hardy | * |
Openssl | Ubuntu | lucid | * |
Openssl | Ubuntu | maverick | * |
Openssl | Ubuntu | natty | * |
Openssl | Ubuntu | oneiric | * |
Openssl098 | Ubuntu | devel | * |
Openssl098 | Ubuntu | oneiric | * |