Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 303739

Summary: <dev-libs/openssl-0.9.8m Memory leak in zlib_stateful_finish() (CVE-2009-4355)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: base-system
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://issues.rpath.com/browse/RPL-3157
Whiteboard: A3 [glsa]
Package list:
Runtime testing required: ---

Description Stefan Behte (RETIRED) gentoo-dev Security 2010-02-06 15:15:07 UTC
CVE-2009-4355 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4355):
  Memory leak in the zlib_stateful_finish function in
  crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta
  through Beta 4 allows remote attackers to cause a denial of service
  (memory consumption) via vectors that trigger incorrect calls to the
  CRYPTO_free_all_ex_data function, as demonstrated by use of SSLv3 and
  PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2010-05-31 11:18:20 UTC
GLSA with bug 308011.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-10-09 15:37:17 UTC
This issue was resolved and addressed in
 201110-01 at http://security.gentoo.org/glsa/glsa-201110-01.xml
by GLSA coordinator Tobias Heinlein (keytoaster).
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2011-10-09 15:37:17 UTC
This issue was resolved and addressed in
 201110-01 at http://security.gentoo.org/glsa/glsa-201110-01.xml
by GLSA coordinator Tobias Heinlein (keytoaster).