HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST)
Published Sep 6, 2011
4.3
MEDIUMCVSS 2.0
EPSS 73.33%
Description
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
Affected products
No data.
Configuration 1
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
- < 3.2.1
Running on/with
- n/a
Configuration 3
- < 3.2.1
Running on/with
- n/a
Configuration 5
- 5.0
- 6.0
- 6.2
- 5.0
- 6.0
- 6.2
- 5.0
- 6.0
Configuration 6
- 5.0
- 6.0
Configuration 7
- 10.04
- 10.10
- 11.04
- 11.10
No data.
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el4
Fixed · RHSA-2012:0006
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el4
Fixed · RHSA-2012:0034
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.29-1jpp.1.el4
Fixed · RHSA-2011:1384
RHEL 4 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el4
Fixed · RHSA-2012:0343
RHEL 5 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el5
Fixed · RHSA-2012:0343
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.23.1.9.10.el5_7
Fixed · RHSA-2011:1380
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.40.1.9.10.el6_1
Fixed · RHSA-2011:1380
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el6
Fixed · RHSA-2012:0034
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-sun-1:1.6.0.29-1jpp.1.el6
Fixed · RHSA-2011:1384
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
Fixed · RHSA-2013:1455
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el5
Fixed · RHSA-2012:0006
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5
Fixed · RHSA-2012:0508
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el5
Fixed · RHSA-2012:0034
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.29-1jpp.1.el5
Fixed · RHSA-2011:1384
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2
Fixed · RHSA-2012:0508
Red Hat Enterprise Linux 4
gnutls
Will not fix
Red Hat Enterprise Linux 4
java-1.5.0-ibm
Affected
Red Hat Enterprise Linux 4
nss
Will not fix
Red Hat Enterprise Linux 4
openssl
Will not fix
Red Hat Enterprise Linux 4
openssl096b
Will not fix
Red Hat Enterprise Linux 5
gnutls
Will not fix
Red Hat Enterprise Linux 5
nss
Affected
Red Hat Enterprise Linux 5
openssl097a
Will not fix
Red Hat Enterprise Linux 6
gnutls
Will not fix
Red Hat Enterprise Linux 6
java-1.4.2-ibm-sap
Affected
Red Hat Enterprise Linux 6
nss
Affected
Red Hat Enterprise Linux 6
openssl
Affected
Red Hat Enterprise Linux 6
openssl098e
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el4 | Fixed | RHSA-2012:0006 |
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el4 | Fixed | RHSA-2012:0034 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.29-1jpp.1.el4 | Fixed | RHSA-2011:1384 |
| RHEL 4 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el4 | Fixed | RHSA-2012:0343 |
| RHEL 5 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.11.sap-1jpp.1.el5 | Fixed | RHSA-2012:0343 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.23.1.9.10.el5_7 | Fixed | RHSA-2011:1380 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.40.1.9.10.el6_1 | Fixed | RHSA-2011:1380 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el6 | Fixed | RHSA-2012:0034 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-sun-1:1.6.0.29-1jpp.1.el6 | Fixed | RHSA-2011:1384 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 | Fixed | RHSA-2013:1455 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.13.11-1jpp.1.el5 | Fixed | RHSA-2012:0006 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5 | Fixed | RHSA-2012:0508 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.10.0-1jpp.2.el5 | Fixed | RHSA-2012:0034 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.29-1jpp.1.el5 | Fixed | RHSA-2011:1384 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2 | Fixed | RHSA-2012:0508 |
| Red Hat Enterprise Linux 4 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 4 | java-1.5.0-ibm | Affected | n/a |
| Red Hat Enterprise Linux 4 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 4 | openssl | Will not fix | n/a |
| Red Hat Enterprise Linux 4 | openssl096b | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | nss | Affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | java-1.4.2-ibm-sap | Affected | n/a |
| Red Hat Enterprise Linux 6 | nss | Affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat is aware of, and tracking, the Rizzo/Duong chosen plain text attack on SSL/TLS 1.0, also known as "BEAST". This issue has been assigned CVE-2011-3389. This attack uses web browser extensions to exploit a weakness in SSL/TLS cipher-block chaining (CBC), allowing a man-in-the-middle attacker to recover certain session information, such as cookie data, from what should be a secure connection. The research shows two ways that an attacker could mount an attack. In both cases the attacker needs access to the data stream from the web browser to the server while a user visits a malicious website using a browser. The attacker may then be able to determine a portion of the data the browser sends to the server by making a large number of requests over a period of time. This data could include information such as an authentication cookie. The first method of attack involves using WebSockets. Currently, Red Hat does not ship any products that allow an attack using WebSockets to be successful. We are planning to update Firefox to version 7, which contains protections in the WebSocket code that prevents this particular attack from being effective. The second method of attack involves using a malicious Java applet. In order for the attack to be successful, the attacker would need to circumvent the Same Origin Policy (SOP) controls in Java. The researchers claim to have found a flaw in the Java SOP and we will issue updates to correct this flaw as suitable fixes are available. We are in contact with various upstream projects regarding this attack. As a precautionary measure, we plan to update the Network Security Services (NSS), GnuTLS, and OpenSSL packages as suitable fixes are available. We will continue to track this issue and take any appropriate actions as needed. This statement and any updates to it is available at: https://bugzilla.redhat.com/show_bug.cgi?id=737506
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (38 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 73.33% (0.73327) | 99.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 73.33% (0.73327) | 99.39th | v5 (v2026.06.15) |
| Mar 4, 2026 | 3.79% (0.03795) | 87.85th | v4 (v2025.03.14) |
| Mar 1, 2026 | 6.67% (0.06669) | 91.10th | v4 (v2025.03.14) |
| Feb 4, 2026 | 3.90% (0.03895) | 87.97th | v4 (v2025.03.14) |
| Feb 1, 2026 | 6.84% (0.06839) | 91.17th | v4 (v2025.03.14) |
| Jan 4, 2026 | 3.79% (0.03795) | 87.73th | v4 (v2025.03.14) |
| Jan 1, 2026 | 6.67% (0.06669) | 90.98th | v4 (v2025.03.14) |
| Dec 4, 2025 | 4.34% (0.04338) | 88.48th | v4 (v2025.03.14) |
| Dec 1, 2025 | 6.84% (0.06839) | 91.03th | v4 (v2025.03.14) |
| Nov 4, 2025 | 4.34% (0.04338) | 88.39th | v4 (v2025.03.14) |
| Nov 1, 2025 | 6.67% (0.06669) | 90.84th | v4 (v2025.03.14) |
| Oct 4, 2025 | 4.63% (0.04632) | 88.81th | v4 (v2025.03.14) |
| Oct 1, 2025 | 7.11% (0.07106) | 91.21th | v4 (v2025.03.14) |
| Sep 4, 2025 | 4.51% (0.04513) | 88.72th | v4 (v2025.03.14) |
| Sep 1, 2025 | 6.93% (0.06930) | 91.09th | v4 (v2025.03.14) |
| Aug 4, 2025 | 5.42% (0.05423) | 89.78th | v4 (v2025.03.14) |
| Aug 1, 2025 | 6.93% (0.06930) | 91.07th | v4 (v2025.03.14) |
| Jul 4, 2025 | 5.42% (0.05423) | 89.69th | v4 (v2025.03.14) |
| Jul 1, 2025 | 6.93% (0.06930) | 90.99th | v4 (v2025.03.14) |
| Jun 4, 2025 | 5.42% (0.05423) | 89.64th | v4 (v2025.03.14) |
| Jun 1, 2025 | 6.93% (0.06930) | 90.95th | v4 (v2025.03.14) |
| May 4, 2025 | 5.42% (0.05423) | 89.59th | v4 (v2025.03.14) |
| May 1, 2025 | 6.93% (0.06930) | 90.93th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.62% (0.04618) | 88.24th | v4 (v2025.03.14) |
| Mar 29, 2025 | 15.60% (0.15602) | 91.19th | v4 (v2025.03.14) |
| Mar 28, 2025 | 4.62% (0.04618) | 88.26th | v4 (v2025.03.14) |
| Mar 27, 2025 | 15.60% (0.15602) | 93.77th | v4 (v2025.03.14) |
| Mar 20, 2025 | 4.62% (0.04618) | 88.33th | v4 (v2025.03.14) |
| Mar 19, 2025 | 15.60% (0.15602) | 93.89th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.62% (0.04618) | 88.54th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.60% (0.00603) | 79.22th | v3 (v2023.03.01) |
| Jul 11, 2024 | 0.85% (0.00854) | 82.39th | v3 (v2023.03.01) |
| Jan 13, 2024 | 0.85% (0.00854) | 80.39th | v3 (v2023.03.01) |
| Nov 19, 2023 | 0.30% (0.00300) | 66.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.21% (0.00211) | 57.18th | v3 (v2023.03.01) |
| Mar 6, 2023 | 40.95% (0.40949) | 98.25th | v2 (v2022.01.01) |
| Feb 4, 2022 | 40.95% (0.40949) | 97.52th | v2 (v2022.01.01) |
References (92)
- http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/ x_refsource_CONFIRMThird Party Advisory
- http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx x_refsource_CONFIRMThird Party Advisory
- http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx x_refsource_CONFIRMThird Party Advisory
- http://curl.haxx.se/docs/adv_20120124B.html x_refsource_CONFIRMThird Party Advisory
- http://downloads.asterisk.org/pub/security/AST-2016-001.html x_refsource_CONFIRMThird Party Advisory
- http://ekoparty.org/2011/juliano-rizzo.php x_refsource_MISCBroken Link
- http://eprint.iacr.org/2004/111 x_refsource_MISCThird Party Advisory
- http://eprint.iacr.org/2006/136 x_refsource_MISCThird Party Advisory
- http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html x_refsource_CONFIRMNot ApplicableVendor Advisory
- http://isc.sans.edu/diary/SSL+TLS+part+3+/11635 x_refsource_MISCThird Party Advisory
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html vendor-advisoryx_refsource_APPLEBroken Link
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html vendor-advisoryx_refsource_APPLEBroken Link
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html vendor-advisoryx_refsource_APPLEBroken LinkMailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html vendor-advisoryx_refsource_SUSEBroken Link
- http://marc.info/?l=bugtraq&m=132750579901589&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=132872385320240&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=133365109612558&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=133728004526190&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=134254957702612&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue x_refsource_CONFIRMThird Party Advisory
- http://osvdb.org/74829 vdb-entryx_refsource_OSVDBBroken Link
- http://rhn.redhat.com/errata/RHSA-2012-0508.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1455.html vendor-advisoryx_refsource_REDHATBroken Link
- http://secunia.com/advisories/45791 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/47998 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48256 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48692 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48915 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/48948 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/49198 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/55322 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/55350 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/55351 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201203-02.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT4999 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT5001 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT5130 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT5281 x_refsource_CONFIRMBroken Link
- http://support.apple.com/kb/HT5501 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT6150 x_refsource_CONFIRMThird Party Advisory
- http://technet.microsoft.com/security/advisory/2588513 x_refsource_CONFIRMPatchVendor Advisory
- http://vnhacker.blogspot.com/2011/09/beast.html x_refsource_MISCThird Party Advisory
- http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2012/dsa-2398 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html x_refsource_MISCBroken Link
- http://www.ibm.com/developerworks/java/jdk/alerts/ x_refsource_CONFIRMThird Party Advisory
- http://www.imperialviolet.org/2011/09/23/chromeandbeast.html x_refsource_CONFIRMThird Party Advisory
- http://www.insecure.cl/Beast-SSL.rar x_refsource_MISCBroken LinkPatch
- http://www.kb.cert.org/vuls/id/864643 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:058 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.opera.com/docs/changelogs/mac/1151/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/docs/changelogs/mac/1160/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/docs/changelogs/unix/1151/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/docs/changelogs/unix/1160/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/docs/changelogs/windows/1151/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/docs/changelogs/windows/1160/ x_refsource_CONFIRMThird Party Advisory
- http://www.opera.com/support/kb/view/1004/ x_refsource_CONFIRMThird Party AdvisoryVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1384.html vendor-advisoryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2012-0006.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/49388 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/49778 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029190 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1025997 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026103 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026704 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1263-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA12-010A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- https://access.redhat.com/security/cve/CVE-2011-3389 Vendor Advisory
- https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=719047 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=737506 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf x_refsource_CONFIRMThird Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 vendor-advisoryx_refsource_HPBroken Link
- https://hermes.opensuse.org/messages/13154861 vendor-advisoryx_refsource_SUSEBroken Link
- https://hermes.opensuse.org/messages/13155432 vendor-advisoryx_refsource_SUSEBroken Link
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://nvd.nist.gov/vuln/detail/CVE-2011-3389
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2011-3389
Change history (0)
No recorded changes yet.