← Back

CVE-2009-4355

nvd nist
Published: Jan 14, 2010Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.

Affected (71)

Products: Openssl: Openssl · Redhat: Openssl
1 product
Openssl
1 product
Openssl
Configuration A
67 vulnerable
Vulnerable SoftwareAffected Versions
Openssl
Up to 0.9.8l
Version 0.9.1c
Version 0.9.2b
Version 0.9.3
Version 0.9.3a
Version 0.9.4
Version 0.9.5
Version 0.9.5 beta1
Version 0.9.5 beta2
Version 0.9.5a
Version 0.9.5a beta1
Version 0.9.5a beta2
Version 0.9.6
Version 0.9.6 beta1
Version 0.9.6 beta2
Version 0.9.6 beta3
Version 0.9.6a
Version 0.9.6a beta1
Version 0.9.6a beta2
Version 0.9.6a beta3
Version 0.9.6b
Version 0.9.6c
Version 0.9.6d
Version 0.9.6e
Version 0.9.6f
Version 0.9.6g
Version 0.9.6h
Version 0.9.6i
Version 0.9.6j
Version 0.9.6k
Version 0.9.6l
Version 0.9.6m
Version 0.9.7
Version 0.9.7 beta1
Version 0.9.7 beta2
Version 0.9.7 beta3
Version 0.9.7 beta4
Version 0.9.7 beta5
Version 0.9.7 beta6
Version 0.9.7a
Version 0.9.7b
Version 0.9.7c
Version 0.9.7d
Version 0.9.7e
Version 0.9.7f
Version 0.9.7g
Version 0.9.7h
Version 0.9.7i
Version 0.9.7j
Version 0.9.7k
Version 0.9.7l
Version 0.9.7m
Version 0.9.8
Version 0.9.8a
Version 0.9.8b
Version 0.9.8c
Version 0.9.8d
Version 0.9.8e
Version 0.9.8f
Version 0.9.8g
Version 0.9.8h
Version 0.9.8i
Version 0.9.8j
Version 0.9.8k
Redhat
Version 0.9.6-15
Version 0.9.6b-3
Version 0.9.7a-2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Openssl
Version 1.0.0 beta1
Version 1.0.0 beta2
Version 1.0.0 beta3
Version 1.0.0 beta4

Related CWEs

References (60)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.