CVE-2009-1387
EPSS 13.5%
Description
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
How to fix CVE-2009-1387
To remediate CVE-2009-1387, upgrade the affected package to a fixed version below.
- Debian/openssl—upgrade to 0.9.8k-2 or later
Is CVE-2009-1387 being exploited?
Moderate — EPSS is 13.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.9.8k-2