openssl: handshake with unseeded PRNG
Published Mar 19, 2015
4.3
MEDIUMCVSS 2.0
EPSS 4.96%
Description
The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and then conducting a brute-force attack.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
Red Hat JBoss Enterprise Web Server 3
openssl
Not affected
Red Hat Storage 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | openssl | Not affected | n/a |
| Red Hat Storage 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, 6, and 7.
References (24)
- http://marc.info/?l=bugtraq&m=143748090628601&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=144050155601375&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=144050297101809&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://www.fortiguard.com/advisory/2015-03-24-openssl-vulnerabilities-march-2015 Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html Third Party Advisory
- http://www.securityfocus.com/bid/73234 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1031929 vdb-entryThird Party AdvisoryVDB Entry
- https://access.redhat.com/articles/1384453
- https://access.redhat.com/security/cve/CVE-2015-0285 Vendor Advisory
- https://bto.bluecoat.com/security-advisory/sa92 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1202410 Issue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-0298 Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=e1b568dd2462f7cacf98f3d117936c34e2849a6b
- https://kc.mcafee.com/corporate/index?page=content&id=SB10110 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-0285
- https://openssl.org/news/secadv_20150319.txt
- https://security.gentoo.org/glsa/201503-11 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2015-0285
- https://www.openssl.org/news/secadv_20150319.txt Vendor Advisory
Change history (0)
No recorded changes yet.