CVE Vulnerabilities

CVE-2005-2969

Published: Oct 18, 2005 | Modified: May 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 0.9.7 (including) 0.9.7 (including)
Openssl Openssl 0.9.7a (including) 0.9.7a (including)
Openssl Openssl 0.9.7b (including) 0.9.7b (including)
Openssl Openssl 0.9.7c (including) 0.9.7c (including)
Openssl Openssl 0.9.7d (including) 0.9.7d (including)
Openssl Openssl 0.9.7e (including) 0.9.7e (including)
Openssl Openssl 0.9.7f (including) 0.9.7f (including)
Openssl Openssl 0.9.7g (including) 0.9.7g (including)
Openssl Openssl 0.9.8 (including) 0.9.8 (including)
Red Hat Enterprise Linux 3 RedHat openssl-0:0.9.7a-33.17 *
Red Hat Enterprise Linux 3 RedHat openssl096b-0:0.9.6b-16.22.4 *
Red Hat Enterprise Linux 4 RedHat openssl-0:0.9.7a-43.4 *
Red Hat Enterprise Linux 4 RedHat openssl096b-0:0.9.6b-22.4 *
Red Hat Network Satellite Server v 4.2 RedHat rhn-solaris-bootstrap-0:5.0.2-3 *
Red Hat Network Satellite Server v 4.2 RedHat rhn_solaris_bootstrap_5_0_2_3-0:1-0 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn-solaris-bootstrap-0:5.0.2-3 *
Red Hat Network Satellite Server v 4.2 (RHEL3) RedHat rhn_solaris_bootstrap_5_0_2_3-0:1-0 *
Red Hat Network Satellite Server v 5.0 RedHat rhn-solaris-bootstrap-0:5.0.2-3 *
Red Hat Network Satellite Server v 5.0 RedHat rhn_solaris_bootstrap_5_0_2_3-0:1-0 *
Red Hat Network Satellite Server v 5.1 RedHat rhn-solaris-bootstrap-0:5.1.1-3 *
Red Hat Network Satellite Server v 5.1 RedHat rhn_solaris_bootstrap_5_1_1_3-0:1-0 *
Red Hat Stronghold 4 RedHat *
Openssl Ubuntu dapper *
Openssl Ubuntu devel *
Openssl Ubuntu edgy *
Openssl Ubuntu feisty *
Openssl097 Ubuntu dapper *
Openssl097 Ubuntu devel *
Openssl097 Ubuntu edgy *
Openssl097 Ubuntu feisty *

References