Double Free Vulnerability in LibreSSL Affects Remote DTLS Handshake
CVE-2014-9424

Currently unrated

Key Information:

Vendor
OpenBSD
Status
Vendor
CVE Published:
29 December 2014

Summary

A double free vulnerability exists in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c of LibreSSL prior to version 2.1.2. This flaw can be exploited by remote attackers to cause a denial of service by triggering a length-verification error during the processing of a DTLS handshake. Exploiting this vulnerability might allow attackers to disrupt secure communications, resulting in potential unauthorized access or information leakage.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.