Description
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-421-1 | openssl security update |
References
History
No history.
Subscriptions
Openssl
Subscribe
Openssl
Subscribe
Oracle
Subscribe
Exalogic Infrastructure
Subscribe
Oss Support Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Tuxedo
Subscribe
Vm Virtualbox
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Aus
Subscribe
Rhel Els
Subscribe
Rhel Eus
Subscribe
Rhel Mission Critical
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T05:39:31.828Z
Reserved: 2015-04-10T00:00:00.000Z
Link: CVE-2015-3197
No data.
Status : Deferred
Published: 2016-02-15T02:59:01.980
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-3197
OpenCVE Enrichment
No data.
Debian DLA