PT-2009-6739 · Apache+15 · Apache Tomcat+24

Marsh Ray

+1

·

Published

1970-01-01

·

Updated

2026-05-27

·

CVE-2009-3555

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8l GnuTLS versions prior to 2.8.5 Apache HTTP Server versions prior to 2.2.14 Microsoft Internet Information Services (IIS) 7.0 OpenVPN versions prior to 2.3.1 Mozilla Network Security Services (NSS) versions prior to 3.12.4 Multiple Cisco products (affected versions not specified) HP Integrated Lights-Out iLO2 and iLO3 (affected versions not specified) FortiOS (affected versions not specified) Apache Tomcat versions prior to 7.0.10, 6.0.32, and 5.5.33 Oracle (affected versions not specified) openSUSE (multiple packages, affected versions not specified) Red Hat Enterprise Linux (multiple packages, affected versions not specified) CentOS (affected versions not specified) Gentoo Linux (multiple packages, affected versions not specified) SUSE Linux Enterprise (multiple packages, affected versions not specified)
Description The vulnerability exists in the TLS/SSL protocol and can be exploited by an unauthenticated, remote attacker to conduct a man-in-the-middle attack. This can be done by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, allowing the attacker to insert data into HTTPS sessions. The attacker can also intercept traffic from a client to a TLS server and appear to authenticate the client to what the client thinks is the desired TLS server. However, the attacker would not be able to view the contents of the session and would only be able to inject data or requests into it.
Recommendations For OpenSSL versions prior to 0.9.8l, update to version 0.9.8l or later. For GnuTLS versions prior to 2.8.5, update to version 2.8.5 or later. For Apache HTTP Server versions prior to 2.2.14, update to version 2.2.14 or later. For Microsoft Internet Information Services (IIS) 7.0, apply the security update provided by Microsoft. For OpenVPN versions prior to 2.3.1, update to version 2.3.1 or later. For Mozilla Network Security Services (NSS) versions prior to 3.12.4, update to version 3.12.4 or later. For HP Integrated Lights-Out iLO2 and iLO3, apply the security update provided by HP. For FortiOS, enable secure renegotiation on the SSL Deep-Inspection. For Apache Tomcat versions prior to 7.0.10, 6.0.32, and 5.5.33, update to version 7.0.10, 6.0.32, or 5.5.33 or later. For Oracle, apply the security update provided by Oracle. For openSUSE, Red Hat Enterprise Linux, CentOS, Gentoo Linux, and SUSE Linux Enterprise, update the affected packages to the latest versions. As a temporary workaround, consider disabling the renegotiation feature in the TLS/SSL protocol until a patch is available. Restrict access to the vulnerable servers and services to minimize the risk of exploitation. Avoid using the vulnerable TLS/SSL protocol versions until the issue is resolved.

Exploit

Fix

DoS

Improper Certificate Validation

RCE

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2015-04270
BDU:2015-04271
BDU:2015-04272
BDU:2015-05174
BDU:2015-05175
BDU:2015-05263
BDU:2015-05264
BDU:2015-05265
BDU:2015-05266
BDU:2015-05267
BDU:2015-05268
BDU:2015-05269
BDU:2015-05270
BDU:2015-05271
BDU:2015-05272
BDU:2015-05273
BDU:2015-05274
BDU:2015-05275
BDU:2015-05276
BDU:2015-05277
BDU:2015-05278
BDU:2015-05279
BDU:2015-05280
BDU:2015-06203
BDU:2015-06204
BDU:2015-07481
BDU:2015-08549
BDU:2015-09404
BDU:2015-09417
BDU:2015-09647
BDU:2015-09682
BDU:2015-09905
CVE-2009-3555
DLA-400-1
DSA-1934-1
DSA-2141-1
DSA-2141-2
DSA-2626-1
DSA-3253-1
GHSA-F7W7-6PJC-WWM6
HPSBUX02482
HPSBUX02498
HPSBUX02517
HPSBUX02524
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10218-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:10268-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:1579
RHSA-2009:1580
RHSA-2009:1694
RHSA-2009_1579
RHSA-2009_1580
RHSA-2010:0011
RHSA-2010:0119
RHSA-2010:0130
RHSA-2010:0155
RHSA-2010:0162
RHSA-2010:0163
RHSA-2010:0164
RHSA-2010:0165
RHSA-2010:0166
RHSA-2010:0167
RHSA-2010:0337
RHSA-2010:0338
RHSA-2010:0339
RHSA-2010:0408
RHSA-2010:0440
RHSA-2010:0768
RHSA-2010:0770
RHSA-2010:0786
RHSA-2010:0807
RHSA-2010:0865
RHSA-2010:0986
RHSA-2010:0987
RHSA-2010_0162
RHSA-2010_0163
RHSA-2010_0164
RHSA-2010_0165
RHSA-2010_0166
RHSA-2010_0167
RHSA-2010_0339
RHSA-2010_0768
RHSA-2010_0865
RHSA-2010_0987
RHSA-2011:0880
RHSA-2015:1591

Affected Products

Apache Http Server
Apache Tomcat
Centos
Cisco
Cisco Asa
Cisco Wls
Fortios
Gentoo Linux
Gnutls
Hp Integrated Lights-Out
Hpe Ilo
Hp-Ux
Internet Information Services
Network Security Services
Nginx
Openssl
Openvpn
Oracle
Oracle Database
Oracle Weblogic Server
Red Hat
Suse Linux Enterprise
Suse
Windows
Opensuse