Back to search

OpenSSL DTLS Fragment Buffer Overflow DoS

This module performs a Denial of Service Attack against Datagram TLS in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h. This occurs when a DTLS ClientHello message has multiple fragments and the fragment lengths of later fragments are larger than that of the first, a buffer overflow occurs, causing a DoS.

Free Metasploit Download

Get your copy of the world's leading penetration testing tool

 Download Now

Module Name

auxiliary/dos/ssl/dtls_fragment_overflow

Authors

  • Juri Aedla <asd [at] ut.ee>
  • Jon Hart <jon_hart [at] rapid7.com>

References

Reliability

Development

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use auxiliary/dos/ssl/dtls_fragment_overflow msf auxiliary(dtls_fragment_overflow) > show actions ...actions... msf auxiliary(dtls_fragment_overflow) > set ACTION <action-name> msf auxiliary(dtls_fragment_overflow) > show options ...show and set options... msf auxiliary(dtls_fragment_overflow) > run

Related Vulnerabilities