Home CVE Database CVE-2016-0703

CVE-2016-0703

Description

The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.

Priority: MEDIUM
CVSS v3: 5.9
Publish Date: Mar 2, 2016
Related ID: --
CVSS v2: Medium
Modified Date: Mar 8, 2016

Find out more about CVE-2016-0703 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Not Vulnerable -- -- --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 7 Fixed LIN7-5730
7.0.0.16 Wind River Linux Security Alert for several openssl security issues
Wind River Linux 7.0.0.14
Wind River Linux 7.0.0.15
Wind River Linux 7.0.0.16
Wind River Linux 7.0.0.17
Wind River Linux 7.0.0.18
Wind River Linux 7.0.0.19
Wind River Linux 7.0.0.20
Wind River Linux 7.0.0.21
Wind River Linux 7.0.0.22
Wind River Linux 7.0.0.23
Wind River Linux 7.0.0.24
Wind River Linux 7.0.0.25
Wind River Linux 7.0.0.26
Wind River Linux 7.0.0.27
Wind River Linux 7.0.0.28
Wind River Linux 7.0.0.29
Wind River Linux 7.0.0.30
Wind River Linux 7.0.0.31
Wind River Linux LTS 18 Not Vulnerable -- -- --
Wind River Linux LTS 19 Not Vulnerable -- -- --
Wind River Linux CD release Not Vulnerable -- -- --
VxWorks
VxWorks 7 Fixed V7SEC-109
openSSL-1.0.4.0 --
VxWorks 6.9 Fixed -- 6.9.4.5 --
VxWorks 6.8 Fixed VXW6-85308
6.8.3 Cumulative Patch VxWorks 6.8.3 Cumulative Networking Source Patch 20160223 for GPP and MSP
VxWorks 6.7 Vulnerable -- -- --
VxWorks 6.6 Vulnerable -- -- --
VxWorks 6.4 Vulnerable -- -- --
VxWorks 5.5 Fixed -- 5.5 Source Patch Wind River VxWorks5.5.1 source point patch for VXW6-83216

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --

Comments

openssl

Live chat
Online