[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-4576Date: (C)2012-01-05   (M)2024-02-22


The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-48528
SECUNIA-55069
SECUNIA-57353
APPLE-SA-2013-06-04-1
DSA-2390
FEDORA-2012-18035
HPSBMU02786
HPSBOV02793
HPSBUX02734
MDVSA-2012:006
MDVSA-2012:007
RHSA-2012:1306
RHSA-2012:1307
RHSA-2012:1308
SSRT100852
SUSE-SU-2012:0084
VU#737740
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc
http://support.apple.com/kb/HT5784
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
http://www.openssl.org/news/secadv_20120104.txt
openSUSE-SU-2012:0083

CPE    62
cpe:/a:openssl:openssl:0.9.1c
cpe:/a:openssl:openssl
cpe:/a:openssl:openssl:1.0.0b
cpe:/a:openssl:openssl:1.0.0a
...
CWE    1
CWE-310
OVAL    20
oval:org.secpod.oval:def:1601328
oval:org.secpod.oval:def:400409
oval:org.secpod.oval:def:600700
oval:org.secpod.oval:def:202264
...

© SecPod Technologies