PT-2011-1174 · Microsoft+9 · Silverlight+14

Jan Lieskovsky

+2

·

Publicado

1999-01-01

·

Atualizado

2026-03-01

·

CVE-2011-3389

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions curl versions prior to 7.24.0 Oracle (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the curl package and Oracle products, which can lead to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. The SSL protocol, used in certain configurations in various products, including Microsoft Windows, Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and others, is vulnerable to a "BEAST" attack. This attack allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack on an HTTPS session, in conjunction with JavaScript code that uses the HTML5 WebSocket API, Java URLConnection API, or Silverlight WebClient API.
Recommendations For curl versions prior to 7.24.0, update to version 7.24.0 or later to mitigate the risk. For Oracle products, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the use of CBC mode with chained initialization vectors in SSL configurations to minimize the risk of exploitation. Restrict access to sensitive data and limit the execution of arbitrary SQL commands to reduce the impact of potential attacks.

Exploit

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09428
CVE-2011-3389
DLA-154-1
DLA-400-1
DSA-2356-1
DSA-2358-1
DSA-2368-1
DSA-2398-1
ECHO-3DD2-4E3E-F5C6
HPSBUX02730
HPSBUX02760
HPSBUX02777
LOWSTRENGTHCIPHERSUITESCHECK
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:10194-1
OPENSUSE-SU-2024:10426-1
OPENSUSE-SU-2024:10451-1
OPENSUSE-SU-2024:10536-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11283-1
OPENSUSE-SU-2024:11284-1
OPENSUSE-SU-2024:11285-1
OPENSUSE-SU-2024:11286-1
OPENSUSE-SU-2024:12089-1
OPENSUSE-SU-2024:12910-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:15713-1
PSF-2011-3
RHSA-2011:1380
RHSA-2011:1384
RHSA-2011_1380
RHSA-2011_1384
RHSA-2012:0006
RHSA-2012:0034
RHSA-2012:0343
RHSA-2012:0508
RHSA-2012_0034
RHSA-2012_0508
RHSA-2013:1455
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2012_0114-1
SUSE-SU-2012_0114-2
SUSE-SU-2012_0122-1
SUSE-SU-2012_0122-2
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1

Produtos afetados

Debian
Google Chrome
Hp-Ux
Java
Java Platform
Internet Explorer
Windows
Firefox
Opera
Oracle
Oracle Database
Red Hat
Silverlight
Suse
Curl