Tracker / CVE-2015-4000
CVE-2015-4000
Bassa 3.7
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Prodotti e versioni affette
| apple | iphone_os · … → 8.3 |
|---|---|
| apple | mac_os_x · … → 10.10.3 |
| apple | safari |
| canonical | ubuntu_linux |
| debian | debian_linux |
| chrome | |
| hp | hp-ux |
| ibm | content_manager |
| microsoft | internet_explorer |
| mozilla | firefox |
| mozilla | firefox_esr |
| mozilla | firefox_os |
| mozilla | network_security_services |
| mozilla | seamonkey |
| mozilla | thunderbird |
| openssl | openssl · … → 1.0.1m |
| openssl | openssl · 1.0.1 → 1.0.1m |
| openssl | openssl · 1.0.2 → 1.0.2a |
| opera | opera_browser |
| oracle | jdk |
| oracle | jre |
| oracle | jrockit |
| oracle | sparc-opl_service_processor · … → 1121 |
| suse | linux_enterprise_desktop |
| suse | linux_enterprise_server |
| suse | linux_enterprise_software_development_kit |
| suse | suse_linux_enterprise_server |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.