Double Free Vulnerability in LibreSSL Affects Remote DTLS Handshake
CVE-2014-9424
Currently unrated
Summary
A double free vulnerability exists in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c of LibreSSL prior to version 2.1.2. This flaw can be exploited by remote attackers to cause a denial of service by triggering a length-verification error during the processing of a DTLS handshake. Exploiting this vulnerability might allow attackers to disrupt secure communications, resulting in potential unauthorized access or information leakage.
References
Timeline
Vulnerability Reserved
Vulnerability published