4.3

CVE-2015-0285

The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and then conducting a brute-force attack.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version1.0.2
OpenSSLOpenSSL Version1.0.2 Updatebeta1
OpenSSLOpenSSL Version1.0.2 Updatebeta2
OpenSSLOpenSSL Version1.0.2 Updatebeta3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.12% 0.905
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
http://marc.info/?l=bugtraq&m=144050155601375&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143748090628601&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144050297101809&w=2
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1031929
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/73234
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1202410
Third Party Advisory
Issue Tracking