PT-2009-2597 · Xyssl · Xyssl

Published

2009-08-31

·

Updated

2017-08-17

·

CVE-2008-7128

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XySSL versions prior to 0.9
Description The issue concerns the ssl parse client key exchange function, which does not protect against certain Bleichenbacher attacks using chosen ciphertext. This allows remote attackers to recover keys via unspecified vectors.
Recommendations For versions prior to 0.9, update to version 0.9 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7128

Affected Products

Xyssl