Codebase list openssl / 9bbe908
Fix "DTLS use after free" (CVE-2009-1379) Kurt Roeckx 14 years ago
2 changed file(s) with 3 addition(s) and 1 deletion(s). Raw diff Collapse all Expand all
44 * Fix security issues (Closes: #530400)
55 - "DTLS record buffer limitation bug." (CVE-2009-1377)
66 - "DTLS fragment handling" (CVE-2009-1378)
7 - "DTLS use after free" (CVE-2009-1379)
78
89 -- Kurt Roeckx <kurt@roeckx.be> Sat, 16 May 2009 17:33:55 +0200
910
529529 frag->fragment,frag->msg_header.frag_len);
530530 }
531531
532 unsigned long frag_len = frag->msg_header.frag_len;
532533 dtls1_hm_fragment_free(frag);
533534 pitem_free(item);
534535
535536 if (al==0)
536537 {
537538 *ok = 1;
538 return frag->msg_header.frag_len;
539 return frag_len;
539540 }
540541
541542 ssl3_send_alert(s,SSL3_AL_FATAL,al);