Lucene search

K
hackeroneRudrahacks007H1:514421
HistoryMar 24, 2019 - 6:26 a.m.

MariaDB: smtp service vulnerable to POODLE SSLv3

2019-03-2406:26:55
rudrahacks007
hackerone.com
28

0.975 High

EPSS

Percentile

100.0%

One of our package servers had an old smtpd service linked with openssl 1.0.1i, which uses nondeterministic CBC padding, making it easy for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the “POODLE” issue. The service has been disabled for the internet, as it was not necessary to begin with.