4.3

CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSLOpenSSL Version >= 1.0.1 <= 1.0.1m
OpenSSLOpenSSL Version >= 1.0.2 <= 1.0.2a
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
CanonicalUbuntu Linux Version15.04
OpenSSLOpenSSL Version <= 1.0.1m
HpHp-ux Versionb.11.31
IbmContent Manager Version8.5 SwPlatformenterprise
OracleJrockit Versionr28.3.6
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
OracleJdk Version1.6.0 Updateupdate95
OracleJdk Version1.7.0 Updateupdate75
OracleJdk Version1.7.0 Updateupdate80
OracleJdk Version1.8.0 Updateupdate_33
OracleJdk Version1.8.0 Updateupdate45
OracleJre Version1.6.0 Updateupdate_95
OracleJre Version1.7.0 Updateupdate_75
OracleJre Version1.7.0 Updateupdate_80
OracleJre Version1.8.0 Updateupdate_33
OracleJre Version1.8.0 Updateupdate_45
SuseLinux Enterprise Server Version11.0 Updatesp4
AppleiPhone OS Version <= 8.3
ApplemacOS X Version <= 10.10.3
OracleSparc-opl Service Processor Version <= 1121
AppleSafari Version-
GoogleChrome Version-
MozillaFirefox Version-
OperaOpera Browser Version-
MozillaFirefox Version38.1.0
MozillaFirefox Version39.0
MozillaFirefox ESR Version31.8
MozillaSeamonkey Version2.35
MozillaThunderbird Version31.8
MozillaThunderbird Version38.1
MozillaFirefox Os Version2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.03% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
http://marc.info/?l=bugtraq&m=144493176821532&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144043644216842&w=2
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/91787
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=144060576831314&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144060606031437&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144069189622016&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144102017024820&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144104533800819&w=2
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1032910
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=143506486712441&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143557934009303&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143558092609708&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143628304012255&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143637549705650&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143655800220052&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143880121627664&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144050121701297&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144061542602287&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=145409266329539&w=2
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2015/05/20/8
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/74733
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032474
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032475
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032476
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032637
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032645
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032647
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032648
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032649
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032650
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032651
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032652
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032653
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032654
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032655
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032656
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032688
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032699
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032702
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032727
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032759
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032777
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032778
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032783
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032784
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032856
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032864
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032865
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032871
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032884
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032932
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032960
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033019
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033064
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033065
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033067
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033208
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033209
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033210
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033222
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033341
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033385
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033416
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033430
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033433
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033513
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033760
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033891
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033991
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034087
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034728
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034884
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036218
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040630
Third Party Advisory
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1138554
Third Party Advisory
Issue Tracking
https://weakdh.org/
Third Party Advisory