VYPR
Unrated severityNVD Advisory· Published Oct 14, 2010· Updated Apr 29, 2026

CVE-2009-5009

CVE-2009-5009

Description

Double free vulnerability in OpenConnect before 1.40 might allow remote AnyConnect SSL VPN servers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted DTLS Cipher option during a reconnect operation.

Affected products

4
  • cpe:2.3:a:infradead:openconnect:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:infradead:openconnect:*:*:*:*:*:*:*:*range: <=1.30
    • cpe:2.3:a:infradead:openconnect:1.00:*:*:*:*:*:*:*
    • cpe:2.3:a:infradead:openconnect:1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:infradead:openconnect:1.20:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.