Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-4108

Опубликовано: 06 янв. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

РелизСтатусПримечание
devel

not-affected

1.0.0g-1ubuntu1
hardy

released

0.9.8g-4ubuntu3.15
lucid

released

0.9.8k-7ubuntu8.8
maverick

released

0.9.8o-1ubuntu4.6
natty

released

0.9.8o-5ubuntu1.2
oneiric

released

1.0.0e-2ubuntu4.2
upstream

released

0.9.8s,1.0.0f

Показывать по

РелизСтатусПримечание
devel

released

0.9.8o-7ubuntu3.1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

released

0.9.8o-7ubuntu1.2
upstream

released

0.9.8s

Показывать по

EPSS

Процентиль: 81%
0.01697
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

nvd
больше 13 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

debian
больше 13 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f ...

github
больше 3 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

oracle-oval
больше 13 лет назад

ELSA-2012-0060: openssl security update (MODERATE)

EPSS

Процентиль: 81%
0.01697
Низкий

4.3 Medium

CVSS2