Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0205

Опубликовано: 09 янв. 2015
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5

Описание

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu10
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.8
lucid

not-affected

precise

not-affected

trusty

released

1.0.1f-1ubuntu2.8
trusty/esm

not-affected

1.0.1f-1ubuntu2.8
upstream

released

1.0.1k
utopic

released

1.0.1f-1ubuntu9.1

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
lucid

DNE

precise

not-affected

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

not-affected

utopic

not-affected

Показывать по

EPSS

Процентиль: 95%
0.19075
Средний

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

nvd
больше 10 лет назад

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

debian
больше 10 лет назад

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before ...

github
около 3 лет назад

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

suse-cvrf
больше 10 лет назад

Security update for compat-openssl098

EPSS

Процентиль: 95%
0.19075
Средний

5 Medium

CVSS2