Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-4180
HistoryDec 06, 2010 - 12:00 a.m.

CVE-2010-4180

2010-12-0600:00:00
ubuntu.com
ubuntu.com
14

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

61.1%

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when
SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly
prevent modification of the ciphersuite in the session cache, which allows
remote attackers to force the downgrade to an unintended cipher via vectors
involving sniffing network traffic to discover a session identifier.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchopenssl<ย 0.9.8a-7ubuntu0.14UNKNOWN
ubuntu8.04noarchopenssl<ย 0.9.8g-4ubuntu3.13UNKNOWN
ubuntu9.10noarchopenssl<ย 0.9.8g-16ubuntu3.5UNKNOWN
ubuntu10.04noarchopenssl<ย 0.9.8k-7ubuntu8.5UNKNOWN
ubuntu10.10noarchopenssl<ย 0.9.8o-1ubuntu4.3UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

61.1%