CVE Vulnerabilities

CVE-2005-2969

Published: Oct 18, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
OpensslOpenssl0.9.7b (including)0.9.7b (including)
OpensslOpenssl0.9.7c (including)0.9.7c (including)
OpensslOpenssl0.9.7d (including)0.9.7d (including)
OpensslOpenssl0.9.7e (including)0.9.7e (including)
OpensslOpenssl0.9.7f (including)0.9.7f (including)
OpensslOpenssl0.9.7g (including)0.9.7g (including)
OpensslOpenssl0.9.8 (including)0.9.8 (including)
Red Hat Enterprise Linux 3RedHatopenssl-0:0.9.7a-33.17*
Red Hat Enterprise Linux 3RedHatopenssl096b-0:0.9.6b-16.22.4*
Red Hat Enterprise Linux 4RedHatopenssl-0:0.9.7a-43.4*
Red Hat Enterprise Linux 4RedHatopenssl096b-0:0.9.6b-22.4*
Red Hat Network Satellite Server v 4.2RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.0RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 5.0RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.1RedHatrhn-solaris-bootstrap-0:5.1.1-3*
Red Hat Network Satellite Server v 5.1RedHatrhn_solaris_bootstrap_5_1_1_3-0:1-0*
Red Hat Stronghold 4RedHat*
OpensslUbuntudapper*
OpensslUbuntudevel*
OpensslUbuntuedgy*
OpensslUbuntufeisty*
Openssl097Ubuntudapper*
Openssl097Ubuntudevel*
Openssl097Ubuntuedgy*
Openssl097Ubuntufeisty*

References