The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2005-10-18T04:00:00
Updated: 2024-08-07T22:53:29.946Z
Reserved: 2005-09-19T00:00:00
Link: CVE-2005-2969
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-10-18T21:02:00.000
Modified: 2024-11-21T00:00:49.890
Link: CVE-2005-2969
Redhat