CVE Vulnerabilities

CVE-2015-4000

Published: May 21, 2015 | Modified: Oct 22, 2024
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the Logjam issue.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 1.0.1 (including) 1.0.1m (including)
Openssl Openssl 1.0.2 (including) 1.0.2a (including)
Oracle Java for Red Hat Enterprise Linux 5 RedHat java-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11 *
Oracle Java for Red Hat Enterprise Linux 5 RedHat java-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11 *
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6 *
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6 *
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1 *
Red Hat Enterprise Linux 5 RedHat openssl-0:0.9.8e-36.el5_11 *
Red Hat Enterprise Linux 5 RedHat java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11 *
Red Hat Enterprise Linux 5 RedHat java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11 *
Red Hat Enterprise Linux 5 Supplementary RedHat java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el5 *
Red Hat Enterprise Linux 5 Supplementary RedHat java-1.7.0-ibm-1:1.7.0.9.10-1jpp.2.el5 *
Red Hat Enterprise Linux 5 Supplementary RedHat java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el5 *
Red Hat Enterprise Linux 6 RedHat openssl-0:1.0.1e-30.el6_6.9 *
Red Hat Enterprise Linux 6 RedHat nss-0:3.19.1-3.el6_6 *
Red Hat Enterprise Linux 6 RedHat nss-util-0:3.19.1-1.el6_6 *
Red Hat Enterprise Linux 6 RedHat java-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6 *
Red Hat Enterprise Linux 6 RedHat java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6 *
Red Hat Enterprise Linux 6 RedHat java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.7.1-ibm-1:1.7.1.3.10-1jpp.3.el6_7 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.5.0-ibm-1:1.5.0.16.13-1jpp.3.el6_7 *
Red Hat Enterprise Linux 7 RedHat openssl-1:1.0.1e-42.el7_1.6 *
Red Hat Enterprise Linux 7 RedHat nss-0:3.19.1-3.el7_1 *
Red Hat Enterprise Linux 7 RedHat nss-util-0:3.19.1-1.ael7b_1 *
Red Hat Enterprise Linux 7 RedHat java-1.8.0-openjdk-1:1.8.0.51-1.b16.el7_1 *
Red Hat Enterprise Linux 7 RedHat java-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.el7_1 *
Red Hat Enterprise Linux 7 RedHat java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1 *
Red Hat JBoss Enterprise Application Platform 6.4 RedHat openssl *
Red Hat JBoss Web Server 3.0 RedHat *
Red Hat Satellite 5.6 RedHat java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 *
Red Hat Satellite 5.7 RedHat java-1.6.0-ibm-1:1.6.0.16.7-1jpp.1.el6_7 *
Supplementary for Red Hat Enterprise Linux 7 RedHat java-1.7.1-ibm-1:1.7.1.3.10-1jpp.1.ael7b_1 *
Apache2 Ubuntu precise *
Firefox Ubuntu artful *
Firefox Ubuntu bionic *
Firefox Ubuntu cosmic *
Firefox Ubuntu devel *
Firefox Ubuntu disco *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu utopic *
Firefox Ubuntu vivid *
Firefox Ubuntu wily *
Firefox Ubuntu xenial *
Firefox Ubuntu yakkety *
Firefox Ubuntu zesty *
Nss Ubuntu artful *
Nss Ubuntu bionic *
Nss Ubuntu cosmic *
Nss Ubuntu devel *
Nss Ubuntu disco *
Nss Ubuntu precise *
Nss Ubuntu trusty *
Nss Ubuntu utopic *
Nss Ubuntu vivid *
Nss Ubuntu vivid/stable-phone-overlay *
Nss Ubuntu wily *
Nss Ubuntu xenial *
Nss Ubuntu yakkety *
Nss Ubuntu zesty *
Openjdk-6 Ubuntu precise *
Openjdk-6 Ubuntu trusty *
Openjdk-6 Ubuntu utopic *
Openjdk-6 Ubuntu vivid *
Openjdk-7 Ubuntu precise *
Openjdk-7 Ubuntu trusty *
Openjdk-7 Ubuntu utopic *
Openjdk-7 Ubuntu vivid *
Openjdk-8 Ubuntu utopic *
Openjdk-8 Ubuntu vivid *
Openjdk-8 Ubuntu wily *
Openssl Ubuntu precise *
Openssl Ubuntu trusty *
Openssl Ubuntu utopic *
Openssl Ubuntu vivid *
Openssl Ubuntu vivid/stable-phone-overlay *
Openssl Ubuntu vivid/ubuntu-core *
Openssl098 Ubuntu precise *
Openssl098 Ubuntu trusty *
Openssl098 Ubuntu utopic *
Openssl098 Ubuntu vivid *
Thunderbird Ubuntu artful *
Thunderbird Ubuntu bionic *
Thunderbird Ubuntu cosmic *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu disco *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu utopic *
Thunderbird Ubuntu vivid *
Thunderbird Ubuntu wily *
Thunderbird Ubuntu xenial *
Thunderbird Ubuntu yakkety *
Thunderbird Ubuntu zesty *

References