PT-2005-1101 · Openssl+3 · Openssl+4

Yutaka Oiwa

·

Published

2005-10-11

·

Updated

2018-05-03

·

CVE-2005-2969

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.7 through 0.9.7h OpenSSL versions 0.9.8 through 0.9.8a
Description The issue concerns a problem in the SSL/TLS server implementation when using the SSL OP MSIE SSLV2 RSA PADDING option, which disables a necessary verification step. This allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack. The vulnerability could also enable an unauthenticated, remote attacker to bypass security restrictions or cause a denial of service, potentially allowing access to encrypted data without knowledge of the encryption key.
Recommendations For OpenSSL versions 0.9.7 through 0.9.7h, update to version 0.9.7h or later to resolve the issue. For OpenSSL versions 0.9.8 through 0.9.8a, update to version 0.9.8a or later to resolve the issue. As a temporary workaround, consider disabling the SSL OP MSIE SSLV2 RSA PADDING option until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09905
CVE-2005-2969
DSA-875-1
DSA-881-1
DSA-882-1
DSA-888-1
HPSBUX02174
RHSA-2005:800
RHSA-2005_800
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629

Affected Products

Cisco Asa
Cisco Ios Xr
Hp-Ux
Openssl
Red Hat