CVE Vulnerabilities

CVE-2011-3389

Inadequate Encryption Strength

Published: Sep 06, 2011 | Modified: Nov 29, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a BEAST attack.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Chrome Google - (including) - (including)
Internet_explorer Microsoft - (including) - (including)
Firefox Mozilla - (including) - (including)
Opera_browser Opera - (including) - (including)
Windows Microsoft - (including) - (including)
Extras for RHEL 4 RedHat java-1.6.0-sun-1:1.6.0.29-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el4 *
Red Hat Enterprise Linux 5 RedHat java-1.6.0-openjdk-1:1.6.0.0-1.23.1.9.10.el5_7 *
Red Hat Enterprise Linux 6 RedHat java-1.6.0-openjdk-1:1.6.0.0-1.40.1.9.10.el6_1 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.6.0-sun-1:1.6.0.29-1jpp.1.el6 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el6 *
Red Hat Network Satellite Server v 5.4 RedHat java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 *
RHEL 4 for SAP RedHat java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el4 *
RHEL 5 for SAP RedHat java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-sun-1:1.6.0.29-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 6 RedHat java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2 *
Lighttpd Ubuntu devel *
Lighttpd Ubuntu hardy *
Lighttpd Ubuntu lucid *
Lighttpd Ubuntu maverick *
Lighttpd Ubuntu natty *
Lighttpd Ubuntu oneiric *
Lighttpd Ubuntu precise *
Lighttpd Ubuntu quantal *
Lighttpd Ubuntu upstream *
Openjdk-6 Ubuntu hardy *
Openjdk-6 Ubuntu lucid *
Openjdk-6 Ubuntu maverick *
Openjdk-6 Ubuntu natty *
Openjdk-6 Ubuntu oneiric *
Openjdk-6b18 Ubuntu lucid *
Openjdk-6b18 Ubuntu maverick *
Openjdk-6b18 Ubuntu natty *
Openjdk-6b18 Ubuntu oneiric *
Openjdk-7 Ubuntu devel *
Openjdk-7 Ubuntu oneiric *
Openjdk-7 Ubuntu precise *
Openjdk-7 Ubuntu quantal *
Sun-java5 Ubuntu hardy *
Sun-java6 Ubuntu hardy *

Potential Mitigations

References