[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2015-3010 -- Oracle openssl

ID: oval:org.secpod.oval:def:1500918Date: (C)2015-02-27   (M)2023-12-07
Class: PATCHFamily: unix




The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role.

Platform:
Oracle Linux 5
Product:
openssl
Reference:
ELSA-2015-3010
CVE-2014-3570
CVE-2014-3571
CVE-2014-3572
CVE-2014-8275
CVE-2015-0204
CVE    5
CVE-2014-3572
CVE-2014-3570
CVE-2014-3571
CVE-2014-8275
...
CPE    28
cpe:/a:openssl:openssl:1.0.0h
cpe:/a:openssl:openssl:1.0.0g
cpe:/a:openssl:openssl:1.0.0j
cpe:/a:openssl:openssl:1.0.0i
...

© SecPod Technologies