SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher
Published Apr 1, 2015
3.7
LOWCVSS 3.1
EPSS 73.85%
Description
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Affected products
No data.
Configuration 1
- ≥ 3.0.0 · ≤ 3.9.0
- < 9.9.2
- 11.1.1.7.0
- 11.1.1.9.0
- 12.1.3.0.0
- 12.2.1.1.0
- 12.2.1.2.0
- ≥ 3.0.0 · ≤ 3.2.11
- ≥ 4.0.0 · ≤ 4.0.4
Configuration 2
- 7.0
- 8.0
Configuration 3
- 5.7
- 5.0
- 6.0
- 7.0
- 6.6
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 5.0
- 6.0
- 7.0
- 6.6
- 7.3
- 7.4
- 7.6
- 7.7
- 7.3
- 7.6
- 7.7
- 5.0
- 6.0
- 7.0
Configuration 4
- 11
- 11
- 13.1
- 13.2
- 11
- 11
- 12
- 10
- 11
- 11
- 11
- 12
- 11
- 12
Configuration 5
Running on/with
- 11
Configuration 6
- 12.04
- 14.04
- 15.04
Configuration 7
Running on/with
- 5.0
- 6.0
Configuration 8
- ≥ xcp · < xcp_1121
Running on/with
- n/a
Configuration 9
- ≥ xcp · < xcp_1121
Running on/with
- n/a
Configuration 10
- ≥ xcp · < xcp_1121
Running on/with
- n/a
Configuration 11
- ≥ xcp · < xcp_1121
Running on/with
- n/a
Configuration 12
- ≥ xcp · < xcp_1121
Running on/with
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Running on/with
- n/a
Configuration 18
- n/a
Running on/with
- n/a
Configuration 19
- n/a
Running on/with
- n/a
Configuration 20
- n/a
Running on/with
- n/a
Configuration 21
- n/a
Running on/with
- n/a
Configuration 22
- n/a
Running on/with
- n/a
Configuration 23
- n/a
Running on/with
- n/a
Configuration 24
- n/a
Running on/with
- n/a
Configuration 25
- n/a
Running on/with
- n/a
Configuration 26
- n/a
Running on/with
- n/a
Configuration 27
- n/a
Running on/with
- n/a
Configuration 28
- n/a
Configuration 29
- n/a
Configuration 30
- n/a
Configuration 31
- n/a
Configuration 32
- n/a
Configuration 33
- n/a
Configuration 34
- n/a
Configuration 35
- n/a
Configuration 36
- n/a
Configuration 37
- n/a
Configuration 38
- n/a
Configuration 39
- n/a
Configuration 40
- n/a
Configuration 41
- n/a
Configuration 42
- n/a
Configuration 43
- n/a
Configuration 44
- n/a
Configuration 45
- n/a
Configuration 46
- n/a
Configuration 47
- n/a
Configuration 48
- n/a
Configuration 49
- n/a
Configuration 50
- n/a
Configuration 51
- n/a
Configuration 52
- v100r003c00
- v100r003c00
- v100r003c10
- v100r002c01
- v100r002c02
- v100r002c03
- v100r002c04
- v100r003c00
Configuration 53
- 10.1
- 10.1.1
- 10.2
- 10.2.1
- 10.2.2
No data.
Oracle Java for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11
Fixed · RHSA-2015:1243
Oracle Java for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11
Fixed · RHSA-2015:1242
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6
Fixed · RHSA-2015:1243
Oracle Java for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6
Fixed · RHSA-2015:1242
Oracle Java for Red Hat Enterprise Linux 6
java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6
Fixed · RHSA-2015:1241
Oracle Java for Red Hat Enterprise Linux 7
java-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1
Fixed · RHSA-2015:1243
Oracle Java for Red Hat Enterprise Linux 7
java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1
Fixed · RHSA-2015:1242
Oracle Java for Red Hat Enterprise Linux 7
java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1
Fixed · RHSA-2015:1241
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11
Fixed · RHSA-2015:1526
Red Hat Enterprise Linux 5
java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11
Fixed · RHSA-2015:1230
Red Hat Enterprise Linux 5 Supplementary
java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5
Fixed · RHSA-2015:1021
Red Hat Enterprise Linux 5 Supplementary
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
Fixed · RHSA-2015:1006
Red Hat Enterprise Linux 5 Supplementary
java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5
Fixed · RHSA-2015:1007
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7
Fixed · RHSA-2015:1526
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6
Fixed · RHSA-2015:1229
Red Hat Enterprise Linux 6
java-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6
Fixed · RHSA-2015:1228
Red Hat Enterprise Linux 7
java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1
Fixed · RHSA-2015:1526
Red Hat Enterprise Linux 7
java-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.ael7b_1
Fixed · RHSA-2015:1229
Red Hat Enterprise Linux 7
java-1.8.0-openjdk-1:1.8.0.51-1.b16.ael7b_1
Fixed · RHSA-2015:1228
Red Hat Satellite 5.6
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
Fixed · RHSA-2015:1091
Red Hat Satellite 5.7
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
Fixed · RHSA-2015:1091
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6
Fixed · RHSA-2015:1021
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
Fixed · RHSA-2015:1006
Supplementary for Red Hat Enterprise Linux 6
java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6
Fixed · RHSA-2015:1020
Supplementary for Red Hat Enterprise Linux 7
java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.ael7b_1
Fixed · RHSA-2015:1020
Red Hat Enterprise Linux 5
gnutls
Will not fix
Red Hat Enterprise Linux 5
nss
Will not fix
Red Hat Enterprise Linux 5
openssl
Affected
Red Hat Enterprise Linux 6
gnutls
Affected
Red Hat Enterprise Linux 6
nss
Will not fix
Red Hat Enterprise Linux 6
openssl
Will not fix
Red Hat Enterprise Linux 7
gnutls
Affected
Red Hat Enterprise Linux 7
nss
Will not fix
Red Hat Enterprise Linux 7
openssl
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el5_11 | Fixed | RHSA-2015:1243 |
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.85-1jpp.1.el5_11 | Fixed | RHSA-2015:1242 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el6_6 | Fixed | RHSA-2015:1243 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el6_6 | Fixed | RHSA-2015:1242 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el6_6 | Fixed | RHSA-2015:1241 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.6.0-sun-1:1.6.0.101-1jpp.1.el7_1 | Fixed | RHSA-2015:1243 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.7.0-oracle-1:1.7.0.85-1jpp.2.el7_1 | Fixed | RHSA-2015:1242 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.8.0-oracle-1:1.8.0.51-1jpp.2.el7_1 | Fixed | RHSA-2015:1241 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el5_11 | Fixed | RHSA-2015:1526 |
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el5_11 | Fixed | RHSA-2015:1230 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5 | Fixed | RHSA-2015:1021 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | Fixed | RHSA-2015:1006 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5 | Fixed | RHSA-2015:1007 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el6_7 | Fixed | RHSA-2015:1526 |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.3.el6_6 | Fixed | RHSA-2015:1229 |
| Red Hat Enterprise Linux 6 | java-1.8.0-openjdk-1:1.8.0.51-0.b16.el6_6 | Fixed | RHSA-2015:1228 |
| Red Hat Enterprise Linux 7 | java-1.6.0-openjdk-1:1.6.0.36-1.13.8.1.el7_1 | Fixed | RHSA-2015:1526 |
| Red Hat Enterprise Linux 7 | java-1.7.0-openjdk-1:1.7.0.85-2.6.1.2.ael7b_1 | Fixed | RHSA-2015:1229 |
| Red Hat Enterprise Linux 7 | java-1.8.0-openjdk-1:1.8.0.51-1.b16.ael7b_1 | Fixed | RHSA-2015:1228 |
| Red Hat Satellite 5.6 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | Fixed | RHSA-2015:1091 |
| Red Hat Satellite 5.7 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | Fixed | RHSA-2015:1091 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6 | Fixed | RHSA-2015:1021 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | Fixed | RHSA-2015:1006 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6 | Fixed | RHSA-2015:1020 |
| Supplementary for Red Hat Enterprise Linux 7 | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.ael7b_1 | Fixed | RHSA-2015:1020 |
| Red Hat Enterprise Linux 5 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 6 | gnutls | Affected | n/a |
| Red Hat Enterprise Linux 6 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | openssl | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | gnutls | Affected | n/a |
| Red Hat Enterprise Linux 7 | nss | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | openssl | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is related to the design of the RC4 protocol and not its implementation. Therefore there are no plans to correct this issue in Red Hat Enterprise Linux 5, 6 and 7. Future updates may disable the use of RC4 in various components.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (48 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 73.85% (0.73851) | 99.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 74.01% (0.74006) | 99.42th | v5 (v2026.06.15) |
| May 29, 2026 | 23.36% (0.23356) | 96.05th | v4 (v2025.03.14) |
| May 28, 2026 | 21.39% (0.21392) | 95.79th | v4 (v2025.03.14) |
| May 24, 2026 | 37.49% (0.37487) | 97.25th | v4 (v2025.03.14) |
| May 13, 2026 | 30.44% (0.30437) | 96.75th | v4 (v2025.03.14) |
| Apr 29, 2026 | 33.88% (0.33875) | 96.98th | v4 (v2025.03.14) |
| Apr 8, 2026 | 30.83% (0.30832) | 96.72th | v4 (v2025.03.14) |
| Mar 31, 2026 | 36.99% (0.36986) | 97.13th | v4 (v2025.03.14) |
| Mar 30, 2026 | 38.04% (0.38035) | 97.19th | v4 (v2025.03.14) |
| Mar 4, 2026 | 32.29% (0.32288) | 96.75th | v4 (v2025.03.14) |
| Mar 1, 2026 | 7.34% (0.07344) | 91.58th | v4 (v2025.03.14) |
| Feb 14, 2026 | 32.29% (0.32288) | 96.72th | v4 (v2025.03.14) |
| Feb 4, 2026 | 35.31% (0.35307) | 96.93th | v4 (v2025.03.14) |
| Feb 1, 2026 | 8.40% (0.08398) | 92.13th | v4 (v2025.03.14) |
| Jan 4, 2026 | 34.74% (0.34742) | 96.87th | v4 (v2025.03.14) |
| Jan 1, 2026 | 8.19% (0.08194) | 91.97th | v4 (v2025.03.14) |
| Dec 28, 2025 | 34.74% (0.34742) | 96.86th | v4 (v2025.03.14) |
| Dec 27, 2025 | 31.27% (0.31266) | 96.62th | v4 (v2025.03.14) |
| Dec 15, 2025 | 34.74% (0.34742) | 96.85th | v4 (v2025.03.14) |
| Dec 4, 2025 | 40.68% (0.40680) | 97.20th | v4 (v2025.03.14) |
| Dec 1, 2025 | 13.69% (0.13688) | 94.03th | v4 (v2025.03.14) |
| Nov 17, 2025 | 40.68% (0.40680) | 97.20th | v4 (v2025.03.14) |
| Nov 4, 2025 | 52.59% (0.52590) | 97.80th | v4 (v2025.03.14) |
| Nov 1, 2025 | 28.42% (0.28415) | 96.32th | v4 (v2025.03.14) |
| Oct 28, 2025 | 52.59% (0.52590) | 97.79th | v4 (v2025.03.14) |
| Oct 27, 2025 | 48.93% (0.48929) | 97.64th | v4 (v2025.03.14) |
| Oct 4, 2025 | 52.59% (0.52590) | 97.85th | v4 (v2025.03.14) |
| Oct 1, 2025 | 28.42% (0.28415) | 96.38th | v4 (v2025.03.14) |
| Sep 4, 2025 | 48.84% (0.48840) | 97.69th | v4 (v2025.03.14) |
| Sep 1, 2025 | 25.20% (0.25196) | 96.02th | v4 (v2025.03.14) |
| Aug 4, 2025 | 48.84% (0.48840) | 97.67th | v4 (v2025.03.14) |
| Aug 1, 2025 | 25.20% (0.25196) | 96.00th | v4 (v2025.03.14) |
| Jul 4, 2025 | 48.84% (0.48840) | 97.63th | v4 (v2025.03.14) |
| Jul 1, 2025 | 25.20% (0.25196) | 95.95th | v4 (v2025.03.14) |
| Jun 4, 2025 | 48.84% (0.48840) | 97.61th | v4 (v2025.03.14) |
| Jun 1, 2025 | 25.20% (0.25196) | 95.91th | v4 (v2025.03.14) |
| May 4, 2025 | 48.84% (0.48840) | 97.59th | v4 (v2025.03.14) |
| May 1, 2025 | 25.20% (0.25196) | 95.88th | v4 (v2025.03.14) |
| Mar 30, 2025 | 48.84% (0.48840) | 97.53th | v4 (v2025.03.14) |
| Mar 29, 2025 | 40.21% (0.40214) | 96.00th | v4 (v2025.03.14) |
| Mar 17, 2025 | 48.71% (0.48706) | 97.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.31% (0.00309) | 70.82th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.30% (0.00300) | 68.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.30% (0.00300) | 64.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 22.69% (0.22690) | 96.64th | v2 (v2022.01.01) |
| May 18, 2022 | 22.69% (0.22690) | 96.40th | v2 (v2022.01.01) |
| Feb 4, 2022 | 22.69% (0.22690) | 94.40th | v2 (v2022.01.01) |
References (106)
- http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034 Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727 Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=143456209711959&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=143629696317098&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=143741441012338&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=143817021313142&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=143817899717054&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=143818140118771&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144043644216842&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144059660127919&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144059703728085&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144060576831314&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144060606031437&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144069189622016&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144102017024820&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144104533800819&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144104565600964&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://marc.info/?l=bugtraq&m=144493176821532&w=2 vendor-advisoryIssue TrackingThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1228.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1229.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1230.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1241.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1242.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1243.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1526.html vendor-advisoryThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV71888 vendor-advisoryThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV71892 vendor-advisoryThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640 Third Party Advisory
- http://www-304.ibm.com/support/docview.wss?uid=swg21903565 Third Party Advisory
- http://www-304.ibm.com/support/docview.wss?uid=swg21960015 Third Party Advisory
- http://www-304.ibm.com/support/docview.wss?uid=swg21960769 Third Party Advisory
- http://www.debian.org/security/2015/dsa-3316 vendor-advisoryThird Party Advisory
- http://www.debian.org/security/2015/dsa-3339 vendor-advisoryThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/hw-454055 Third Party Advisory
- http://www.imperva.com/docs/HII_Attacking_SSL_when_using_RC4.pdf
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html Third Party Advisory
- http://www.securityfocus.com/bid/73684 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/91787 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032599 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032600 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032707 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032708 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032734 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032788 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032858 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032868 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032910 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032990 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033071 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033072 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033386 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033415 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033431 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033432 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033737 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033769 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036222 vdb-entryThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2696-1 vendor-advisoryThird Party Advisory
- http://www.ubuntu.com/usn/USN-2706-1 vendor-advisoryThird Party Advisory
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htm Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-2808 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1207101 Issue Tracking
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04687922 vendor-advisoryThird Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246 Third Party Advisory
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789 Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650 Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888 Third Party Advisory
- https://kb.juniper.net/JSA10783 Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10163 Broken Link
- https://nvd.nist.gov/vuln/detail/CVE-2015-2808
- https://security.gentoo.org/glsa/201512-10 vendor-advisoryThird Party Advisory
- https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709 Third Party Advisory
- https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf Technical DescriptionThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2015-2808
- https://www.secpod.com/blog/cve-2015-2808-bar-mitzvah-attack-in-rc4-2/
Change history (0)
No recorded changes yet.