openssl: allow remote attackers to reuse SSL sessions and bypass access controls
Published Jan 4, 2000
6.5
MEDIUMCVSS 3.1
EPSS 3.23%
Description
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
Affected products
No data.
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
openssl
Not affected
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
mingw-openssl
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenSSL, as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8, is not affected by this flaw because newer versions of OpenSSL that have already been patched are shipped. This vulnerability was originally published over 20 years ago. It affects OpenSSL versions < 0.92b, which are not shipped in Red Hat products.
References (5)
- http://www.osvdb.org/3936 vdb-entryx_refsource_OSVDBBroken Link
- https://access.redhat.com/security/cve/CVE-1999-0428 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1891836 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-1999-0428
- https://www.cve.org/CVERecord?id=CVE-1999-0428
| Link | Providers | Tags |
|---|---|---|
| http://www.osvdb.org/3936 | vdb-entryx_refsource_OSVDBBroken Link | |
| https://access.redhat.com/security/cve/CVE-1999-0428 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1891836 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-1999-0428 | ||
| https://www.cve.org/CVERecord?id=CVE-1999-0428 |
Change history (0)
No recorded changes yet.