Home CVE Database CVE-2016-0704

CVE-2016-0704

Description

An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.

Priority: MEDIUM
CVSS v3: 5.9
Publish Date: Mar 2, 2016
Related ID: --
CVSS v2: Medium
Modified Date: Mar 11, 2016

Find out more about CVE-2016-0704 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Not Vulnerable -- -- --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 7 Fixed LIN7-5731
7.0.0.16 Wind River Linux Security Alert for several openssl security issues
Wind River Linux 7.0.0.14
Wind River Linux 7.0.0.15
Wind River Linux 7.0.0.16
Wind River Linux 7.0.0.17
Wind River Linux 7.0.0.18
Wind River Linux 7.0.0.19
Wind River Linux 7.0.0.20
Wind River Linux 7.0.0.21
Wind River Linux 7.0.0.22
Wind River Linux 7.0.0.23
Wind River Linux 7.0.0.24
Wind River Linux 7.0.0.25
Wind River Linux 7.0.0.26
Wind River Linux 7.0.0.27
Wind River Linux 7.0.0.28
Wind River Linux 7.0.0.29
Wind River Linux 7.0.0.30
Wind River Linux 7.0.0.31
Wind River Linux LTS 18 Not Vulnerable -- -- --
Wind River Linux LTS 19 Not Vulnerable -- -- --
Wind River Linux CD release Not Vulnerable -- -- --
VxWorks
VxWorks 7 Fixed V7SEC-109
openSSL-1.0.4.0 --
VxWorks 6.9 Fixed -- 6.9.4.5 --
VxWorks 6.8 Fixed VXW6-85308
6.8.3 Cumulative Patch VxWorks 6.8.3 Cumulative Networking Source Patch 20160223 for GPP and MSP
VxWorks 6.7 Vulnerable -- -- --
VxWorks 6.6 Vulnerable -- -- --
VxWorks 6.4 Vulnerable -- -- --
VxWorks 5.5 Fixed -- 5.5 Source Patch Wind River VxWorks5.5.1 source point patch for VXW6-83216

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --

Comments

openssl

Live chat
Online