(HP Issues Fix) OpenSSL zlib Initialization Error Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1023888 |
|
SecurityTracker URL: http://securitytracker.com/id/1023888
|
|
CVE Reference:
CVE-2009-4355
(Links to External Site)
|
Date: Apr 15 2010
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 0.9.8l, possibly other versions
|
Description:
A vulnerability was reported in OpenSSL. A remote user can cause denial of service conditions.
The software does not properly free unused memory in certain situations. A remote user can send specially crafted data to trigger a memory leak and cause the target service to consume excessive memory resources.
The vulnerability resides in 'openssl/crypto/comp/c_zlib.c'.
|
Impact:
A remote user can cause to consume excessive memory resources.
|
Solution:
HP has issued a fix for HP-UX.
The HP advisory is available at:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02079216
|
Vendor URL: www.openssl.org/ (Links to External Site)
|
Cause:
Resource error
|
Underlying OS:
UNIX (HP/UX)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Thu, 15 Apr 2010 03:42:20 +0000
Subject: HPSBUX02517 SSRT100058 rev.1 - HP-UX Running OpenSSL, Remote Unauthorized Information Disclosure, Unauthorized Data Modification, Denial of Service (DoS)
|
CVE-2009-4355
|
|