CVE Vulnerabilities

CVE-2011-4576

Published: Jan 06, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*0.9.8r (including)
OpensslOpenssl0.9.1c (including)0.9.1c (including)
OpensslOpenssl0.9.2b (including)0.9.2b (including)
OpensslOpenssl0.9.4 (including)0.9.4 (including)
OpensslOpenssl0.9.5 (including)0.9.5 (including)
OpensslOpenssl0.9.5a (including)0.9.5a (including)
OpensslOpenssl0.9.6 (including)0.9.6 (including)
OpensslOpenssl0.9.6a (including)0.9.6a (including)
OpensslOpenssl0.9.6b (including)0.9.6b (including)
OpensslOpenssl0.9.6c (including)0.9.6c (including)
OpensslOpenssl0.9.6d (including)0.9.6d (including)
OpensslOpenssl0.9.6e (including)0.9.6e (including)
OpensslOpenssl0.9.6f (including)0.9.6f (including)
OpensslOpenssl0.9.6g (including)0.9.6g (including)
OpensslOpenssl0.9.6h (including)0.9.6h (including)
OpensslOpenssl0.9.6h-bogus (including)0.9.6h-bogus (including)
OpensslOpenssl0.9.6i (including)0.9.6i (including)
OpensslOpenssl0.9.6j (including)0.9.6j (including)
OpensslOpenssl0.9.6k (including)0.9.6k (including)
OpensslOpenssl0.9.6l (including)0.9.6l (including)
OpensslOpenssl0.9.6m (including)0.9.6m (including)
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
OpensslOpenssl0.9.7b (including)0.9.7b (including)
OpensslOpenssl0.9.7c (including)0.9.7c (including)
OpensslOpenssl0.9.7d (including)0.9.7d (including)
OpensslOpenssl0.9.7e (including)0.9.7e (including)
OpensslOpenssl0.9.7f (including)0.9.7f (including)
OpensslOpenssl0.9.7g (including)0.9.7g (including)
OpensslOpenssl0.9.7h (including)0.9.7h (including)
OpensslOpenssl0.9.7i (including)0.9.7i (including)
OpensslOpenssl0.9.7j (including)0.9.7j (including)
OpensslOpenssl0.9.7k (including)0.9.7k (including)
OpensslOpenssl0.9.7l (including)0.9.7l (including)
OpensslOpenssl0.9.7m (including)0.9.7m (including)
OpensslOpenssl0.9.8 (including)0.9.8 (including)
OpensslOpenssl0.9.8a (including)0.9.8a (including)
OpensslOpenssl0.9.8b (including)0.9.8b (including)
OpensslOpenssl0.9.8c (including)0.9.8c (including)
OpensslOpenssl0.9.8d (including)0.9.8d (including)
OpensslOpenssl0.9.8e (including)0.9.8e (including)
OpensslOpenssl0.9.8f (including)0.9.8f (including)
OpensslOpenssl0.9.8g (including)0.9.8g (including)
OpensslOpenssl0.9.8h (including)0.9.8h (including)
OpensslOpenssl0.9.8i (including)0.9.8i (including)
OpensslOpenssl0.9.8j (including)0.9.8j (including)
OpensslOpenssl0.9.8k (including)0.9.8k (including)
OpensslOpenssl0.9.8l (including)0.9.8l (including)
OpensslOpenssl0.9.8m (including)0.9.8m (including)
OpensslOpenssl0.9.8n (including)0.9.8n (including)
OpensslOpenssl0.9.8o (including)0.9.8o (including)
OpensslOpenssl0.9.8p (including)0.9.8p (including)
OpensslOpenssl0.9.8q (including)0.9.8q (including)
Red Hat Enterprise Linux 4RedHatopenssl-0:0.9.7a-43.18.el4*
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-20.el5_7.1*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.0-20.el6_2.1*
Red Hat JBoss Enterprise Application Platform 5.1RedHat*
Red Hat JBoss Enterprise Application Platform 6.0RedHat*
Red Hat JBoss Web Server 1.0RedHat*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.2-20120209.0.el6_2*
OpensslUbuntuhardy*
OpensslUbuntulucid*
OpensslUbuntumaverick*
OpensslUbuntunatty*
OpensslUbuntuoneiric*
OpensslUbuntuupstream*
Openssl098Ubuntudevel*
Openssl098Ubuntuoneiric*
Openssl098Ubuntuupstream*

References