RULE(RULE ID:805207)

Rule General Information
Release Date: 2015-10-26
Rule Name: PROTOCOL-SSL Openssl DTLS Dtls1_buffer_record Denial of Service Vulnerability -2 (CVE-2015-0206)
Severity:
CVE ID:
Rule Protection Details
Description: Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:71940
SecurityFocusBID:91787
SecurityTrackerID:1033378
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.openssl.org/news/secadv_20150108.txt