Lucene search

K
hackeroneDadrianH1:138179
HistoryMay 12, 2016 - 5:53 a.m.

Internet Bug Bounty: Divide-and-conquer session key recovery in SSLv2 (CVE-2016-0703)

2016-05-1205:53:22
dadrian
hackerone.com
35

0.009 Low

EPSS

Percentile

83.0%

This is a retroactive submission of CVE-2016-0703, a.k.a. the “Extra Clear” bug, which can lead to the Special DROWN variant of the DROWN attack. After some discussion with the other DROWN authors, I’m submitting on behalf of myself (David Adrian) and J. Alex Halderman the vulnerability CVE-2016-0703, which was acknowledged by OpenSSL as Sev:High at https://www.openssl.org/news/secadv/20160301.txt.