Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 303739 - <dev-libs/openssl-0.9.8m Memory leak in zlib_stateful_finish() (CVE-2009-4355)
Summary: <dev-libs/openssl-0.9.8m Memory leak in zlib_stateful_finish() (CVE-2009-4355)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: https://issues.rpath.com/browse/RPL-3157
Whiteboard: A3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-02-06 15:15 UTC by Stefan Behte (RETIRED)
Modified: 2011-10-09 15:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-02-06 15:15:07 UTC
CVE-2009-4355 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4355):
  Memory leak in the zlib_stateful_finish function in
  crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta
  through Beta 4 allows remote attackers to cause a denial of service
  (memory consumption) via vectors that trigger incorrect calls to the
  CRYPTO_free_all_ex_data function, as demonstrated by use of SSLv3 and
  PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2010-05-31 11:18:20 UTC
GLSA with bug 308011.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-10-09 15:37:17 UTC
This issue was resolved and addressed in
 201110-01 at http://security.gentoo.org/glsa/glsa-201110-01.xml
by GLSA coordinator Tobias Heinlein (keytoaster).
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2011-10-09 15:37:17 UTC
This issue was resolved and addressed in
 201110-01 at http://security.gentoo.org/glsa/glsa-201110-01.xml
by GLSA coordinator Tobias Heinlein (keytoaster).