PT-2013-1148 · Openssl+11 · Openssl+16

Karthikeyan Bhargavan

·

Published

2013-12-01

·

Updated

2025-12-23

·

CVE-2015-0204

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k openssl-1.0.1e openssl-devel-1.0.1e openssl-static-1.0.1e openssl-libs-1.0.1e openssl-debuginfo-1.0.1e
Description The issue allows remote SSL servers to conduct RSA-to-EXPORT RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue. This can lead to a denial of service condition or allow an attacker to gain access to sensitive data. The vulnerability can be exploited remotely.
Recommendations For versions prior to 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k, update to a version that includes the fix for this issue. For openssl-1.0.1e, openssl-devel-1.0.1e, openssl-static-1.0.1e, openssl-libs-1.0.1e, and openssl-debuginfo-1.0.1e, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the ssl3 get key exchange function until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2015-1023
ALT-PU-2015-2113
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
BDU:2015-09960
BDU:2015-09963
CESA-2015_0066
CVE-2015-0204
DLA-132-1
DSA-3125-1
ELSA-2015-0066
HPSBUX03162
HPSBUX03244
HPSBUX03334
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015:0800
RHSA-2015_0066
RHSA-2015_0800
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0305-1
SUSE-SU-2015:0343-1
SUSE-SU-2015:0343-2
SUSE-SU-2015:0344-1
SUSE-SU-2015:0392-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0547-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1086-1
SUSE-SU-2015:1086-2
SUSE-SU-2015:1086-3
SUSE-SU-2015:1086-4
SUSE-SU-2015:1161-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1183-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-2015:2166-1
SUSE-SU-2015:2168-1
SUSE-SU-2015:2168-2
SUSE-SU-2015:2182-1
SUSE-SU-2015:2192-1
SUSE-SU-2015:2216-1
SUSE-SU-2015_0578-1
SUSE-SU-2015_1085-1
SUSE-SU-2015_1086-1
SUSE-SU-2015_1086-2
SUSE-SU-2015_1086-3
SUSE-SU-2015_1138-1
SUSE-SU-2015_1161-1
SUSE-SU-2015_2166-1
SUSE-SU-2015_2168-1
SUSE-SU-2015_2168-2
SUSE-SU-2015_2182-1
SUSE-SU-2015_2192-1
SUSE-SU-2015_2216-1
SUSE-SU-403
USN-2459-1

Affected Products

Alt Linux
Centos
Check Point Gaia
Cisco Asa
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Cisco Wls
Hp-Ux
Ibm Aix
Java Platform
Junos
Openssl
Oracle Database
Red Hat
Suse
Ubuntu