CVE Vulnerabilities

CVE-2015-4000

Published: May 21, 2015 | Modified: Apr 12, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the Logjam issue.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl1.0.1 (including)1.0.1m (including)
OpensslOpenssl1.0.2 (including)1.0.2a (including)
Oracle Java for Red Hat Enterprise Linux 5RedHatjava-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11*
Oracle Java for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1*
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-36.el5_11*
Red Hat Enterprise Linux 5RedHatjava-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.7.0-ibm-1:1.7.0.9.10-1jpp.2.el5*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el5*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-30.el6_6.9*
Red Hat Enterprise Linux 6RedHatnss-0:3.19.1-3.el6_6*
Red Hat Enterprise Linux 6RedHatnss-util-0:3.19.1-1.el6_6*
Red Hat Enterprise Linux 6RedHatjava-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6*
Red Hat Enterprise Linux 6RedHatjava-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6*
Red Hat Enterprise Linux 6RedHatjava-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.7.1-ibm-1:1.7.1.3.10-1jpp.3.el6_7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el6_7*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-42.ael7b_1.6*
Red Hat Enterprise Linux 7RedHatnss-0:3.19.1-3.ael7b_1*
Red Hat Enterprise Linux 7RedHatnss-util-0:3.19.1-1.el7_1*
Red Hat Enterprise Linux 7RedHatjava-1.8.0-openjdk-1:1.8.0.51-1.b16.ael7b_1*
Red Hat Enterprise Linux 7RedHatjava-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.ael7b_1*
Red Hat Enterprise Linux 7RedHatjava-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1*
Red Hat JBoss Enterprise Application Platform 6.4RedHatopenssl*
Red Hat JBoss Web Server 3.0RedHat*
Red Hat Satellite 5.6RedHatjava-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7*
Red Hat Satellite 5.7RedHatjava-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7*
Supplementary for Red Hat Enterprise Linux 7RedHatjava-1.7.1-ibm-1:1.7.1.3.10-1jpp.1.el7_1*
Apache2Ubuntuprecise*
FirefoxUbuntuartful*
FirefoxUbuntubionic*
FirefoxUbuntucosmic*
FirefoxUbuntudevel*
FirefoxUbuntudisco*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuutopic*
FirefoxUbuntuvivid*
FirefoxUbuntuwily*
FirefoxUbuntuxenial*
FirefoxUbuntuyakkety*
FirefoxUbuntuzesty*
NssUbuntuartful*
NssUbuntubionic*
NssUbuntucosmic*
NssUbuntudevel*
NssUbuntudisco*
NssUbuntuesm-infra-legacy/trusty*
NssUbuntuesm-infra/bionic*
NssUbuntuesm-infra/xenial*
NssUbuntuprecise*
NssUbuntutrusty*
NssUbuntutrusty/esm*
NssUbuntuutopic*
NssUbuntuvivid*
NssUbuntuvivid/stable-phone-overlay*
NssUbuntuwily*
NssUbuntuxenial*
NssUbuntuyakkety*
NssUbuntuzesty*
Openjdk-6Ubuntuprecise*
Openjdk-6Ubuntutrusty*
Openjdk-6Ubuntuutopic*
Openjdk-6Ubuntuvivid*
Openjdk-7Ubuntuprecise*
Openjdk-7Ubuntutrusty*
Openjdk-7Ubuntuutopic*
Openjdk-7Ubuntuvivid*
Openjdk-8Ubuntuutopic*
Openjdk-8Ubuntuvivid*
Openjdk-8Ubuntuwily*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuutopic*
OpensslUbuntuvivid*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*
Openssl098Ubuntuutopic*
Openssl098Ubuntuvivid*
ThunderbirdUbuntuartful*
ThunderbirdUbuntubionic*
ThunderbirdUbuntucosmic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntudisco*
ThunderbirdUbuntuprecise*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuutopic*
ThunderbirdUbuntuvivid*
ThunderbirdUbuntuwily*
ThunderbirdUbuntuxenial*
ThunderbirdUbuntuyakkety*
ThunderbirdUbuntuzesty*

References