4.3

CVE-2010-4180

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSLOpenSSL Version < 0.9.8q
OpenSSLOpenSSL Version >= 1.0.0 < 1.0.0c
FedoraprojectFedora Version13
FedoraprojectFedora Version14
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version10.10
OpensuseOpensuse Version11.1
OpensuseOpensuse Version11.2
OpensuseOpensuse Version11.3
OpensuseOpensuse Version11.4
SuseLinux Enterprise Version11.0 Updatesp1
SuseLinux Enterprise Desktop Version10 Updatesp3
SuseLinux Enterprise Desktop Version10 Updatesp4 SwEdition-
SuseLinux Enterprise Desktop Version11 Updatesp1
SuseLinux Enterprise Server Version10 Updatesp3 SwEdition-
SuseLinux Enterprise Server Version10 Updatesp4 SwEdition-
F5Nginx Version < 0.9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.99% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
http://marc.info/?l=bugtraq&m=132077688910227&w=2
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/archive/1/522176
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=129916880600544&w=2
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=130497251507577&w=2
Third Party Advisory
Issue Tracking
http://www.kb.cert.org/vuls/id/737740
Third Party Advisory
US Government Resource
http://ubuntu.com/usn/usn-1029-1
Third Party Advisory
http://www.securityfocus.com/bid/45164
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1024822
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=659462
Patch
Third Party Advisory
Issue Tracking