Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3566

Опубликовано: 15 окт. 2014
Источник: debian
EPSS Критический

Описание

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
aroraunfixedpackage
bouncycastlenot-affectedpackage
chromium-browserfixed39.0.2171.71-1package
chromium-browserend-of-lifewheezypackage
chromium-browserend-of-lifesqueezepackage
conkerorunfixedpackage
cyasslremovedpackage
wolfsslfixed3.4.8+dfsg-1package
dwbunfixedpackage
opensslfixed1.0.1j-1package
opensslno-dsawheezypackage
opensslno-dsasqueezepackage
galeonunfixedpackage
gnutls26removedpackage
gnutls26no-dsasqueezepackage
gnutls26no-dsawheezypackage
gnutls28fixed3.3.8-5package
kazehakaseunfixedpackage
kdebaseremovedpackage
kde-baseappsunfixedpackage
epiphany-browserunfixedpackage
haskell-tlsfixed1.2.9-2package
haskell-tlsno-dsawheezypackage
icedovefixed31.3.0-1package
icedoveend-of-lifesqueezepackage
iceweaselfixed31.2.0esr-2package
iceweaselend-of-lifesqueezepackage
matrixsslremovedpackage
matrixsslno-dsasqueezepackage
matrixsslno-dsawheezypackage
midoriunfixedpackage
netsurffixed3.6-1package
nssfixed2:3.17.1-1package
nssno-dsasqueezepackage
nssno-dsawheezypackage
openjdk-6fixed6b34-1.13.6-1package
openjdk-7fixed7u75-2.5.4-1package
openjdk-8fixed8u40~b04-1package
polarsslfixed1.3.9-2package
polarsslno-dsasqueezepackage
polarsslno-dsawheezypackage
poundfixed2.6-6package
poundno-dsasqueezepackage
surfunfixedpackage
tlsliteremovedpackage
tlsliteno-dsawheezypackage
uzblunfixedpackage
erlangfixed1:17.3-dfsg-3package
erlangno-dsasqueezepackage
erlangno-dsawheezypackage
lighttpdfixed1.4.35-4package

Примечания

  • http://www.kb.cert.org/vuls/id/BLUU-9PYTFQ

  • wolfssl actually fixed with the initial upload to unstable after the rename

  • https://bugs.launchpad.net/ubuntu/+source/gnutls26/+bug/1510163

  • https://www.openssl.org/~bodo/ssl-poodle.pdf

  • http://googleonlinesecurity.blogspot.fr/2014/10/this-poodle-bites-exploiting-ssl-30.html

  • This is only about the SSLv3 CBC padding, not about any downgrade attack or support for the fallback SCSV

  • Fix is to disable SSLv3 in library or application configurations

  • Browsers based on webkit (with the exception of Chromium) or khtml are not covered by security support

EPSS

Процентиль: 100%
0.9413
Критический

Связанные уязвимости

CVSS3: 3.4
ubuntu
почти 11 лет назад

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

redhat
почти 11 лет назад

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVSS3: 3.4
nvd
почти 11 лет назад

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

suse-cvrf
больше 8 лет назад

Security update for slrn

suse-cvrf
около 10 лет назад

Recommended update for Package Management Stack

EPSS

Процентиль: 100%
0.9413
Критический