CVE-2013-6450
Publication date 1 January 2014
Last updated 24 July 2024
Ubuntu priority
The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
Notes
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-2079-1
- OpenSSL vulnerabilities
- 9 January 2014