Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3099

Опубликовано: 05 апр. 2016
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

A flaw was found in the way mod_nss parsed certain OpenSSL-style cipher strings. As a result, mod_nss could potentially use ciphers that were not intended to be enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 8mod_nssWill not fix
Red Hat Enterprise Linux 5mod_nssWill not fix
Red Hat Enterprise Linux 6mod_nssWill not fix
Red Hat Enterprise Linux 7mod_nssFixedRHSA-2016:260203.11.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-392
https://bugzilla.redhat.com/show_bug.cgi?id=1319052mod_nss: Invalid handling of +CIPHER operator

EPSS

Процентиль: 51%
0.0028
Низкий

1.9 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

CVSS3: 7.5
nvd
больше 8 лет назад

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

CVSS3: 7.5
debian
больше 8 лет назад

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux ...

CVSS3: 7.5
github
больше 3 лет назад

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

oracle-oval
почти 9 лет назад

ELSA-2016-2602: mod_nss security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 51%
0.0028
Низкий

1.9 Low

CVSS2