CVE-2010-4180
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an…
Does this matter?
Lower severity and a low EPSS score (9.50%). Track it; it rarely justifies an emergency change on its own.
Description
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 9.50% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- openssl/openssl · fedoraproject/fedora · debian/debian linux · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise · suse/linux enterprise desktop · suse/linux enterprise server · f5/nginx
- Source
- secalert@redhat.com
References
- http://cvs.openssl.org/chngview?cn=20131Broken Link, Patch
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777Broken Link
- http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052027.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052315.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=129916880600544&w=2Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=130497251507577&w=2Issue Tracking, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132077688910227&w=2Issue Tracking, Third Party Advisory
- http://openssl.org/news/secadv_20101202.txtPatch, Third Party Advisory
- http://osvdb.org/69565Broken Link
- http://secunia.com/advisories/42469Not Applicable
- http://secunia.com/advisories/42473Not Applicable
- http://secunia.com/advisories/42493Not Applicable
- http://secunia.com/advisories/42571Not Applicable
- http://secunia.com/advisories/42620Not Applicable
- http://secunia.com/advisories/42811Not Applicable
- http://secunia.com/advisories/42877Not Applicable
- http://secunia.com/advisories/43169Not Applicable
- http://secunia.com/advisories/43170Not Applicable
- http://secunia.com/advisories/43171Not Applicable
- http://secunia.com/advisories/43172Not Applicable
- http://secunia.com/advisories/43173Not Applicable
- http://secunia.com/advisories/44269Not Applicable
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471Third Party Advisory
- http://support.apple.com/kb/HT4723Third Party Advisory
- http://ubuntu.com/usn/usn-1029-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.