CVE-2009-1386
Openssl < 0.9.8i - NULL Pointer Dereference
Title source: ruleDescription
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Jon Oberheide · cdosmultiple
https://www.exploit-db.com/exploits/8873
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ssl/dtls_changecipherspec.rb
References (21)
... and 1 more
Scores
EPSS
0.4763
EPSS Percentile
97.7%
Details
CWE
CWE-476
Status
published
Products (8)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
8.10
canonical/ubuntu_linux
9.04
openssl/openssl
0.9.8 - 0.9.8i
redhat/openssl
0.9.6-15
redhat/openssl
0.9.6b-3
redhat/openssl
0.9.7a-2
Published
Jun 04, 2009
Tracked Since
Feb 18, 2026