openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
Published Dec 6, 2010
4.3
MEDIUMCVSS 2.0
EPSS 9.50%
Description
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Affected products
No data.
Configuration 1
Configuration 2
- 13
- 14
Configuration 3
- 5.0
Configuration 4
- 6.06
- 8.04
- 9.04
- 10.04
- 10.10
Configuration 5
- 11.1
- 11.2
- 11.3
- 11.4
- 11.0
- 10
- 10
- 11
- 9
- 10
- 10
No data.
Red Hat Enterprise Linux 4
openssl-0:0.9.7a-43.17.el4_8.6
Fixed · RHSA-2010:0977
Red Hat Enterprise Linux 5
openssl-0:0.9.8e-12.el5_5.7
Fixed · RHSA-2010:0978
Red Hat Enterprise Linux 6
openssl-0:1.0.0-4.el6_0.2
Fixed · RHSA-2010:0979
Red Hat JBoss Web Server 1.0
n/a
Fixed · RHSA-2011:0896
Red Hat Enterprise Linux 4
openssl096b
Will not fix
Red Hat Enterprise Linux 5
openssl097a
Will not fix
Red Hat Enterprise Linux 6
openssl098e
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | openssl-0:0.9.7a-43.17.el4_8.6 | Fixed | RHSA-2010:0977 |
| Red Hat Enterprise Linux 5 | openssl-0:0.9.8e-12.el5_5.7 | Fixed | RHSA-2010:0978 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.0-4.el6_0.2 | Fixed | RHSA-2010:0979 |
| Red Hat JBoss Web Server 1.0 | n/a | Fixed | RHSA-2011:0896 |
| Red Hat Enterprise Linux 4 | openssl096b | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (53)
- http://cvs.openssl.org/chngview?cn=20131 x_refsource_CONFIRMBroken LinkPatch
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777 vendor-advisoryx_refsource_HPBroken Link
- http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html vendor-advisoryx_refsource_APPLEBroken LinkMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052027.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052315.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=129916880600544&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=130497251507577&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=132077688910227&w=2 vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory
- http://openssl.org/news/secadv_20101202.txt x_refsource_CONFIRMPatchThird Party Advisory
- http://osvdb.org/69565 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/42469 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42473 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42493 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42571 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42620 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42811 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/42877 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/43169 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/43170 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/43171 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/43172 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/43173 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/44269 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471 vendor-advisoryx_refsource_SLACKWAREThird Party Advisory
- http://support.apple.com/kb/HT4723 x_refsource_CONFIRMThird Party Advisory
- http://ubuntu.com/usn/usn-1029-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.debian.org/security/2011/dsa-2141 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.kb.cert.org/vuls/id/737740 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:248 vendor-advisoryx_refsource_MANDRIVAPermissions Required
- http://www.redhat.com/support/errata/RHSA-2010-0977.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0978.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0979.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0896.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/522176 vendor-advisoryx_refsource_HPThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/45164 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1024822 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2010/3120 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2010/3122 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2010/3134 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2010/3188 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2011/0032 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2011/0076 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2011/0268 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2010-4180 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=659462 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA53&actp=LIST x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2010-4180
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18910 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2010-4180
| Link | Providers | Tags |
|---|---|---|
| http://cvs.openssl.org/chngview?cn=20131 | x_refsource_CONFIRMBroken LinkPatch | |
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777 | vendor-advisoryx_refsource_HPBroken Link | |
| http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html | vendor-advisoryx_refsource_APPLEBroken LinkMailing ListThird Party Advisory | |
| http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052027.html | vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory | |
| http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052315.html | vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=129916880600544&w=2 | vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=130497251507577&w=2 | vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory | |
| http://marc.info/?l=bugtraq&m=132077688910227&w=2 | vendor-advisoryx_refsource_HPIssue TrackingThird Party Advisory | |
| http://openssl.org/news/secadv_20101202.txt | x_refsource_CONFIRMPatchThird Party Advisory | |
| http://osvdb.org/69565 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://secunia.com/advisories/42469 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42473 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42493 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42571 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42620 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42811 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/42877 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/43169 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/43170 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/43171 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/43172 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/43173 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://secunia.com/advisories/44269 | third-party-advisoryx_refsource_SECUNIANot Applicable | |
| http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471 | vendor-advisoryx_refsource_SLACKWAREThird Party Advisory | |
| http://support.apple.com/kb/HT4723 | x_refsource_CONFIRMThird Party Advisory | |
| http://ubuntu.com/usn/usn-1029-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.debian.org/security/2011/dsa-2141 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.kb.cert.org/vuls/id/737740 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:248 | vendor-advisoryx_refsource_MANDRIVAPermissions Required | |
| http://www.redhat.com/support/errata/RHSA-2010-0977.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.redhat.com/support/errata/RHSA-2010-0978.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.redhat.com/support/errata/RHSA-2010-0979.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.redhat.com/support/errata/RHSA-2011-0896.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://www.securityfocus.com/archive/1/522176 | vendor-advisoryx_refsource_HPThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/45164 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1024822 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.vupen.com/english/advisories/2010/3120 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2010/3122 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2010/3134 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2010/3188 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2011/0032 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2011/0076 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2011/0268 | vdb-entryx_refsource_VUPENPermissions Required | |
| https://access.redhat.com/security/cve/CVE-2010-4180 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=659462 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://kb.bluecoat.com/index?page=content&id=SA53&actp=LIST | x_refsource_CONFIRMBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-4180 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18910 | vdb-entrysignaturex_refsource_OVALThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2010-4180 |
Change history (0)
No recorded changes yet.