The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the Logjam issue.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 1.0.1 (including) | 1.0.1m (including) |
Openssl | Openssl | 1.0.2 (including) | 1.0.2a (including) |
Oracle Java for Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11 | * |
Oracle Java for Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1 | * |
Red Hat Enterprise Linux 5 | RedHat | openssl-0:0.9.8e-36.el5_11 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.7.0-ibm-1:1.7.0.9.10-1jpp.2.el5 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el5 | * |
Red Hat Enterprise Linux 6 | RedHat | openssl-0:1.0.1e-30.el6_6.9 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-0:3.19.1-3.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-util-0:3.19.1-1.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.7.1-ibm-1:1.7.1.3.10-1jpp.3.el6_7 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el6_7 | * |
Red Hat Enterprise Linux 7 | RedHat | openssl-1:1.0.1e-42.el7_1.6 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-0:3.19.1-3.el7_1 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-util-0:3.19.1-1.ael7b_1 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-openjdk-1:1.8.0.51-1.b16.el7_1 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.el7_1 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1 | * |
Red Hat JBoss Enterprise Application Platform 6.4 | RedHat | openssl | * |
Red Hat JBoss Web Server 3.0 | RedHat | * | |
Red Hat Satellite 5.6 | RedHat | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 | * |
Red Hat Satellite 5.7 | RedHat | java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 | * |
Supplementary for Red Hat Enterprise Linux 7 | RedHat | java-1.7.1-ibm-1:1.7.1.3.10-1jpp.1.ael7b_1 | * |
Apache2 | Ubuntu | precise | * |
Firefox | Ubuntu | artful | * |
Firefox | Ubuntu | bionic | * |
Firefox | Ubuntu | cosmic | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | disco | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | utopic | * |
Firefox | Ubuntu | vivid | * |
Firefox | Ubuntu | wily | * |
Firefox | Ubuntu | xenial | * |
Firefox | Ubuntu | yakkety | * |
Firefox | Ubuntu | zesty | * |
Nss | Ubuntu | artful | * |
Nss | Ubuntu | bionic | * |
Nss | Ubuntu | cosmic | * |
Nss | Ubuntu | devel | * |
Nss | Ubuntu | disco | * |
Nss | Ubuntu | precise | * |
Nss | Ubuntu | trusty | * |
Nss | Ubuntu | utopic | * |
Nss | Ubuntu | vivid | * |
Nss | Ubuntu | vivid/stable-phone-overlay | * |
Nss | Ubuntu | wily | * |
Nss | Ubuntu | xenial | * |
Nss | Ubuntu | yakkety | * |
Nss | Ubuntu | zesty | * |
Openjdk-6 | Ubuntu | precise | * |
Openjdk-6 | Ubuntu | trusty | * |
Openjdk-6 | Ubuntu | utopic | * |
Openjdk-6 | Ubuntu | vivid | * |
Openjdk-7 | Ubuntu | precise | * |
Openjdk-7 | Ubuntu | trusty | * |
Openjdk-7 | Ubuntu | utopic | * |
Openjdk-7 | Ubuntu | vivid | * |
Openjdk-8 | Ubuntu | utopic | * |
Openjdk-8 | Ubuntu | vivid | * |
Openjdk-8 | Ubuntu | wily | * |
Openssl | Ubuntu | precise | * |
Openssl | Ubuntu | trusty | * |
Openssl | Ubuntu | utopic | * |
Openssl | Ubuntu | vivid | * |
Openssl | Ubuntu | vivid/stable-phone-overlay | * |
Openssl | Ubuntu | vivid/ubuntu-core | * |
Openssl098 | Ubuntu | precise | * |
Openssl098 | Ubuntu | trusty | * |
Openssl098 | Ubuntu | utopic | * |
Openssl098 | Ubuntu | vivid | * |
Thunderbird | Ubuntu | artful | * |
Thunderbird | Ubuntu | bionic | * |
Thunderbird | Ubuntu | cosmic | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | disco | * |
Thunderbird | Ubuntu | precise | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | upstream | * |
Thunderbird | Ubuntu | utopic | * |
Thunderbird | Ubuntu | vivid | * |
Thunderbird | Ubuntu | wily | * |
Thunderbird | Ubuntu | xenial | * |
Thunderbird | Ubuntu | yakkety | * |
Thunderbird | Ubuntu | zesty | * |