PT-2016-1595 · Openssl+7 · Openssl+7

Nimrod Aviram

+1

·

Published

2016-01-28

·

Updated

2024-06-15

·

CVE-2015-3197

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 before 1.0.1r OpenSSL versions 1.0.2 before 1.0.2f
Description The issue is related to errors in cryptographic transformations in the OpenSSL library, specifically in the ssl/s2 srvr.c function. This can be exploited by a remote attacker to compromise the cryptographic protection mechanism by performing computations on SSLv2 traffic, related to the get client master key and get client hello functions. The vulnerability makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms.
Recommendations For OpenSSL versions 1.0.1 before 1.0.1r, update to version 1.0.1r or later. For OpenSSL versions 1.0.2 before 1.0.2f, update to version 1.0.2f or later. As a temporary workaround, consider disabling the use of SSLv2 traffic until a patch is available. Restrict access to the get client master key and get client hello functions to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1058
BDU:2016-00896
CESA-2016_0301
CESA-2016_0372
CVE-2015-3197
DLA-421-1
FREEBSD-SA-16_11
MGASA-2016-0056
OPENSUSE-SU-2016_0628-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2016_0720-1
OPENSUSE-SU-2016_1241-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:0301
RHSA-2016:0302
RHSA-2016:0303
RHSA-2016:0304
RHSA-2016:0305
RHSA-2016:0306
RHSA-2016:0372
RHSA-2016:0379
RHSA-2016_0301
RHSA-2016_0302
RHSA-2016_0372
SUSE-FU-2022:0445-1
SUSE-SU-2016:0617-1
SUSE-SU-2016:0620-1
SUSE-SU-2016:0621-1
SUSE-SU-2016:0624-1
SUSE-SU-2016:0631-1
SUSE-SU-2016:0641-1
SUSE-SU-2016:0748-1
SUSE-SU-2016:0778-1
SUSE-SU-2016:0786-1
SUSE-SU-2016:1057-1
SUSE-SU-2016_0617-1
SUSE-SU-2016_0620-1
SUSE-SU-2016_0621-1
SUSE-SU-2016_0624-1
SUSE-SU-2016_0631-1
SUSE-SU-2016_0641-1

Affected Products

Alt Linux
Centos
Freebsd
Ibm Aix
Openssl
Red Hat
Suse
Virtualbox