Heap
10-07-08, 23:11
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1678)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1678)