Lucene search

K
hackeroneNimiaH1:166629
HistorySep 07, 2016 - 5:34 p.m.

Internet Bug Bounty: Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)

2016-09-0717:34:32
nimia
hackerone.com
30

0.952 High

EPSS

Percentile

99.4%

General DROWN was responsibly disclosed to the OpenSSL team prior to the public disclosure.
This OpenSSL blog post, by Viktor Dukhovni and Emilia Käsper, describes the vulnerability:
https://www.openssl.org/blog/blog/2016/03/01/an-openssl-users-guide-to-drown/

This is probably a good opportunity to again thank everyone who helped with the disclosure process :-)