OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
BID:44107
Info
OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
| Bugtraq ID: | 44107 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-5009 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2009 12:00AM |
| Updated: | May 27 2009 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
OpenConnect is prone to a remote denial-of-service vulnerability due to a double-free error.
Successful exploits may allow an attacker to crash the affected application, resulting in a denial-of-service condition. Other attacks may also be possible.
Versions prior to OpenConnect 1.40 are vulnerable.
OpenConnect is prone to a remote denial-of-service vulnerability due to a double-free error.
Successful exploits may allow an attacker to crash the affected application, resulting in a denial-of-service condition. Other attacks may also be possible.
Versions prior to OpenConnect 1.40 are vulnerable.
Exploit / POC
OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
Attackers can exploit the issue using readily available network tools
Attackers can exploit the issue using readily available network tools
Solution / Fix
OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
OpenConnect DTLS Cipher Option Remote Denial Of Service Vulnerability
References:
References:
- OpenConnect Homepage (OpenConnect)