The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 0.9.7 (including) | 0.9.7 (including) |
Openssl | Openssl | 0.9.7a (including) | 0.9.7a (including) |
Openssl | Openssl | 0.9.7b (including) | 0.9.7b (including) |
Openssl | Openssl | 0.9.7c (including) | 0.9.7c (including) |
Openssl | Openssl | 0.9.7d (including) | 0.9.7d (including) |
Openssl | Openssl | 0.9.7e (including) | 0.9.7e (including) |
Openssl | Openssl | 0.9.7f (including) | 0.9.7f (including) |
Openssl | Openssl | 0.9.7g (including) | 0.9.7g (including) |
Openssl | Openssl | 0.9.8 (including) | 0.9.8 (including) |
Red Hat Enterprise Linux 3 | RedHat | openssl-0:0.9.7a-33.17 | * |
Red Hat Enterprise Linux 3 | RedHat | openssl096b-0:0.9.6b-16.22.4 | * |
Red Hat Enterprise Linux 4 | RedHat | openssl-0:0.9.7a-43.4 | * |
Red Hat Enterprise Linux 4 | RedHat | openssl096b-0:0.9.6b-22.4 | * |
Red Hat Network Satellite Server v 4.2 | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 4.2 | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 4.2 (RHEL3) | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 4.2 (RHEL3) | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 5.0 | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 5.0 | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 5.1 | RedHat | rhn-solaris-bootstrap-0:5.1.1-3 | * |
Red Hat Network Satellite Server v 5.1 | RedHat | rhn_solaris_bootstrap_5_1_1_3-0:1-0 | * |
Red Hat Stronghold 4 | RedHat | * | |
Openssl | Ubuntu | dapper | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | edgy | * |
Openssl | Ubuntu | feisty | * |
Openssl097 | Ubuntu | dapper | * |
Openssl097 | Ubuntu | devel | * |
Openssl097 | Ubuntu | edgy | * |
Openssl097 | Ubuntu | feisty | * |