Vulnerability CVE-2015-0206: Information
Description
Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.
Severity: MEDIUM (5.0)
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
openssl10 | p9 | 1.0.1k-alt1 | 1.0.2u-alt1.p9.2 | ALT-PU-2015-1023-1 | 138366 | Fixed |
openssl10 | c9f2 | 1.0.1k-alt1 | 1.0.2u-alt1.p9.1 | ALT-PU-2015-1023-1 | 138366 | Fixed |
openssl10 | c7 | 1.0.1k-alt1.M70C.1 | 1.0.1u-alt0.M70C.1 | ALT-PU-2015-1030-1 | 138378 | Fixed |