Lucene search

K
freebsdFreeBSD77B784BB-3DC6-11E4-B191-F0DEF16C5C1B
HistorySep 16, 2014 - 12:00 a.m.

nginx -- inject commands into SSL session vulnerability

2014-09-1600:00:00
vuxml.freebsd.org
32

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.6%

The nginx project reports:

Security: it was possible to reuse SSL sessions in unrelated contexts
if a shared SSL session cache or the same TLS session ticket key was
used for multiple “server” blocks (CVE-2014-3616).

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

61.6%