PT-2005-1101 · Openssl+3 · Openssl+4

Yutaka Oiwa

·

Publicado

2005-10-11

·

Atualizado

2018-05-03

·

CVE-2005-2969

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.7 through 0.9.7h OpenSSL versions 0.9.8 through 0.9.8a
Description The issue concerns a problem in the SSL/TLS server implementation when using the SSL OP MSIE SSLV2 RSA PADDING option, which disables a necessary verification step. This allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack. The vulnerability could also enable an unauthenticated, remote attacker to bypass security restrictions or cause a denial of service, potentially allowing access to encrypted data without knowledge of the encryption key.
Recommendations For OpenSSL versions 0.9.7 through 0.9.7h, update to version 0.9.7h or later to resolve the issue. For OpenSSL versions 0.9.8 through 0.9.8a, update to version 0.9.8a or later to resolve the issue. As a temporary workaround, consider disabling the SSL OP MSIE SSLV2 RSA PADDING option until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09905
CVE-2005-2969
DSA-875-1
DSA-881-1
DSA-882-1
DSA-888-1
HPSBUX02174
RHSA-2005:800
RHSA-2005_800
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629

Produtos afetados

Cisco Asa
Cisco Ios Xr
Hp-Ux
Openssl
Red Hat