Show plain JSON{"id": "CVE-2009-4355", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2010-01-14T19:30:00.390", "references": [{"url": "http://cvs.openssl.org/chngview?cn=19068", "source": "cve@mitre.org"}, {"url": "http://cvs.openssl.org/chngview?cn=19069", "source": "cve@mitre.org"}, {"url": "http://cvs.openssl.org/chngview?cn=19167", "source": "cve@mitre.org"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html", "source": "cve@mitre.org"}, {"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html", "source": "cve@mitre.org"}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html", "source": "cve@mitre.org"}, {"url": "http://marc.info/?l=bugtraq&m=127128920008563&w=2", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/38175", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/38181", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/38200", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/38761", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/39461", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/42724", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/42733", "source": "cve@mitre.org"}, {"url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049", "source": "cve@mitre.org"}, {"url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0004", "source": "cve@mitre.org"}, {"url": "http://www.debian.org/security/2010/dsa-1970", "source": "cve@mitre.org"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:022", "source": "cve@mitre.org"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/13/3", "source": "cve@mitre.org"}, {"url": "http://www.ubuntu.com/usn/USN-884-1", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2010/0124", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2010/0839", "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2010/0916", "source": "cve@mitre.org"}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=546707", "source": "cve@mitre.org"}, {"url": "https://issues.rpath.com/browse/RPL-3157", "source": "cve@mitre.org"}, {"url": "https://kb.bluecoat.com/index?page=content&id=SA50", "source": "cve@mitre.org"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11260", "source": "cve@mitre.org"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12168", "source": "cve@mitre.org"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6678", "source": "cve@mitre.org"}, {"url": "https://rhn.redhat.com/errata/RHSA-2010-0095.html", "source": "cve@mitre.org"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-399"}]}], "descriptions": [{"lang": "en", "value": "Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678."}, {"lang": "es", "value": "Fuga de memoria en la funci\u00f3n zlib_stateful_finish en crypto/comp/c_zlib.c en OpenSSL v0.9.8l y anteriores, y v1.0.0 Beta a la Beta 4, permite a atacantes remoso provocar una denegaci\u00f3n de servicio (consumo de memoria) a trav\u00e9s de vectores que provocan llamadas incorrectas a la funci\u00f3n CRYPTO_free_all_ex_data, como se demostr\u00f3 usando SSLv3 y PHP con el Apache HTTP Server, una cuesti\u00f3n relacionada con el CVE-2008-1678."}], "lastModified": "2017-09-19T01:29:57.657", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81FB3B26-CC83-4FA5-BDE1-05F35AB99741", "versionEndIncluding": "0.9.8l"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14D983EC-61B0-4FD9-89B5-9878E4CE4405"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5D7BE3C-8CA2-4FB2-B4AE-B201D88C2A9D"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC4C5F05-BC0B-478D-9A6F-7C804777BA41"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27F417A1-5D97-4BC4-8B97-5AC40236DA21"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8847BD34-BDE6-4AE9-96D9-75B9CF93A6A8"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EDB5A09-BE86-4352-9799-A875649EDB7D"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6231CAA-00A8-41CE-8436-B84518014CF1"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A70AD93B-E876-4EAB-9970-752D42E15E99"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F03FA9C0-24C7-46AC-92EC-7834BC34C79B"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "716ADA01-38B8-4C15-A3BB-D9688DA30599"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.5a:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B73326F7-7DCE-4EDE-95D7-AE7AED263A14"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5E4742C-A983-4F00-B24F-AB280C0E876D"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA2D251C-9C45-4EFE-8262-E88AB7CE713A"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D81E175-E698-40EF-9601-425893FFB1FC"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA0F25B7-A172-4300-8718-112E817A6165"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A0628DF-3A4C-4078-B615-22260671EABF"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52B1BE89-BAE0-4656-943B-B9B81D9B54B3"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D097222B-ED20-459C-9167-55751FA2C87A"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6a:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86DDC8F2-7920-4A73-927E-562C89806972"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "962FCB86-15AD-4399-8B7D-EC1DEA919C59"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FCA45CE-4127-47AD-BBA8-8A6DD83AE1C7"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CA1CA40-7DB5-4DCA-97A8-9A8CF4FECECC"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "180D07AE-C571-4DD6-837C-43E2A946007A"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA3E4D2A-6488-4F8B-A3CA-4161A10FA4DB"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90789533-C741-4B1C-A24B-2C77B9E4DE5F"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1520065B-46D7-48A4-B9D0-5B49F690C5B4"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B76FE2D-FBE0-4A3B-A0EA-179332D74F0E"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6j:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AA526B9-726A-49D5-B3CA-EBE2DA303CA0"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "494E48E7-EF86-4860-9A53-94F6C313746E"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6l:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2636B92E-47D5-42EA-9585-A2B84FBE71CB"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.6m:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72FE2F46-2D0C-4C90-AFBE-D2E7B496D6E4"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45A518E8-21BE-4C5C-B425-410AB1208E9C"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E3AB748-E463-445C-ABAB-4FEDDFD1878B"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "660E4B8D-AABA-4520-BC4D-CF8E76E07C05"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85BFEED5-4941-41BB-93D1-CD5C2A41290E"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9644CC68-1E91-45E7-8C53-1E3FC9976A4E"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B1B98C4-1FFD-4A7C-AA86-A34BC6F7AB31"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73934717-2DA3-4614-A076-D6EDA5EB0626"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78E79A05-64F3-4397-952C-A5BB950C967D"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F7C9E77-1EB2-4720-A8FD-23DC1C877D5A"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "549BB01D-F322-4FE3-BDA2-4FEA8ED8568A"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DE6CBD6-D6DD-4BC5-93F6-FDEA70163336"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98693865-2E79-4BD6-9F89-1994BC9A3E73"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6476506-EC37-4726-82DC-D0E8254A8CDD"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D6ECEF7-CB16-4604-894B-6EB19F1CEF55"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C81EF3D-4DB7-4799-9670-8D79E28CA184"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8116A66-175C-4E6D-9A9B-D54C1D97D213"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "382C1679-DA1D-4FA4-9D5E-B86CC5052D49"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CA28812-8A24-4FE1-BED9-D6D5BB023645"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7l:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9894D83E-2A27-446E-8B47-9C03CF802A2B"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.7m:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55A9AC4D-E19B-431F-8679-B62F5F46BCF7"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A4E446D-B9D3-45F2-9722-B41FA14A6C31"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF4EA988-FC80-4170-8933-7C6663731981"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64F8F53B-24A1-4877-B16E-F1917C4E4E81"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75D3ACD5-905F-42BB-BE1A-8382E9D823BF"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "766EA6F2-7FA4-4713-9859-9971CCD2FDCB"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EFBC30B7-627D-48DC-8EF0-AE8FA0C6EDBA"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BB38AEA-BAF0-4920-9A71-747C24444770"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F33EA2B-DE15-4695-A383-7A337AC38908"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "261EE631-AB43-44FE-B02A-DFAAB8D35927"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA0E0BBF-D0BE-41A7-B9BB-C28F01000BC0"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A1365ED-4651-4AB2-A64B-43782EA2F0E8"}, {"criteria": "cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC82690C-DCED-47BA-AA93-4D0C9E95B806"}, {"criteria": "cpe:2.3:a:redhat:openssl:0.9.6-15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B8C80A1-D1E7-42D4-8DBC-CB7637D7598E"}, {"criteria": "cpe:2.3:a:redhat:openssl:0.9.6b-3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EB3990A-3457-4CD6-9EEC-F2D4BC143932"}, {"criteria": "cpe:2.3:a:redhat:openssl:0.9.7a-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06110A61-8857-46D5-BEE1-882197756DED"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A2075BD-6102-4B0F-839A-836E9585F43B"}, {"criteria": "cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A2FA09E-2BF7-4968-B62D-00DA57F81EA1"}, {"criteria": "cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F02E634E-1E3D-4E44-BADA-76F92483A732"}, {"criteria": "cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCC2B07A-49EF-411F-8A4D-89435E22B043"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}