PT-2009-6750 · Openssl+3 · Openssl+4

Tomas Hoger

·

Published

1970-01-01

·

Updated

2022-08-04

·

CVE-2010-4180

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8q OpenSSL versions 1.0.x prior to 1.0.0c openssl-devel-0.9.7a openssl-0.9.7a compat-openssl097g compat-openssl097g-32bit openssl (prior to version 1.0.0e)
Description The issue involves multiple vulnerabilities in the OpenSSL package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially allowing attackers to force the downgrade to an unintended cipher or gain unauthorized access to encrypted data. The vulnerabilities may also lead to a denial of service or unauthorized modification.
Recommendations For OpenSSL versions prior to 0.9.8q, update to version 0.9.8q or later. For OpenSSL versions 1.0.x prior to 1.0.0c, update to version 1.0.0c or later. For openssl-devel-0.9.7a, update to a version that is not affected by the vulnerability. For openssl-0.9.7a, update to a version that is not affected by the vulnerability. For compat-openssl097g, update to a version that is not affected by the vulnerability. For compat-openssl097g-32bit, update to a version that is not affected by the vulnerability. For openssl (prior to version 1.0.0e), update to version 1.0.0e or later. As a temporary workaround, consider restricting access to the vulnerable SSL/TLS implementation until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05174
BDU:2015-05175
BDU:2015-06475
BDU:2015-06478
BDU:2015-08472
BDU:2015-08473
BDU:2015-09418
BDU:2015-09905
CVE-2010-4180
DSA-2141-1
HPSBUX02638
RHSA-2010:0977
RHSA-2010:0978
RHSA-2010:0979
RHSA-2010_0977
RHSA-2010_0978
RHSA-2010_0979
SUSE-SU-2013_1165-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Hpe Ilo
Hp-Ux
Openssl
Red Hat
Suse