imPC@ndo EN

Tracker / CVE-2015-4000

CVE-2015-4000

Bassa 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Prodotti e versioni affette

apple iphone_os · … → 8.3
apple mac_os_x · … → 10.10.3
apple safari
canonical ubuntu_linux
debian debian_linux
google chrome
hp hp-ux
ibm content_manager
microsoft internet_explorer
mozilla firefox
mozilla firefox_esr
mozilla firefox_os
mozilla network_security_services
mozilla seamonkey
mozilla thunderbird
openssl openssl · … → 1.0.1m
openssl openssl · 1.0.1 → 1.0.1m
openssl openssl · 1.0.2 → 1.0.2a
opera opera_browser
oracle jdk
oracle jre
oracle jrockit
oracle sparc-opl_service_processor · … → 1121
suse linux_enterprise_desktop
suse linux_enterprise_server
suse linux_enterprise_software_development_kit
suse suse_linux_enterprise_server

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti