Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4000

Опубликовано: 21 мая 2015
Источник: debian
EPSS Критический

Описание

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.0.2b-1package
nssfixed2:3.19.1-1package
nssno-dsasqueezepackage
openjdk-6fixed6b36-1.13.8-1experimentalpackage
openjdk-6removedpackage
openjdk-7fixed7u79-2.5.6-1package
openjdk-8fixed8u66-b01-1package
icedovefixed38.1.0-1package

Примечания

  • CVE assigned specific to vulnerability in the TLS protocol that was

  • disclosed in section 3.2 of the

  • https://weakdh.org/imperfect-forward-secrecy.pdf paper.

  • Some links on the status of various implementations/protocols:

  • IKE/IPSEC: https://nohats.ca/wordpress/blog/2015/05/20/weakdh-and-ike-ipsec/

  • OpenSSL: https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/

  • OpenSSL 1.0.2b-1 limits it to 768 bit, future versions will increase the limit

  • GNUTLS: http://lists.gnutls.org/pipermail/gnutls-devel/2015-May/007597.html

  • NSS/iceweasel/icedove: https://www.mozilla.org/en-US/security/advisories/mfsa2015-70/

  • NSS patch increasing limit to 1023 bits: https://hg.mozilla.org/projects/nss/rev/ae72d76f8d24

EPSS

Процентиль: 100%
0.93815
Критический

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
redhat
около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
nvd
около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

suse-cvrf
почти 9 лет назад

Security update for libtcnative-1-0

suse-cvrf
больше 9 лет назад

Security update for socat

EPSS

Процентиль: 100%
0.93815
Критический