imPC@ndo IT

Tracker / CVE-2015-4000

CVE-2015-4000

Low 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Affected products and versions

apple iphone_os · … → 8.3
apple mac_os_x · … → 10.10.3
apple safari
canonical ubuntu_linux
debian debian_linux
google chrome
hp hp-ux
ibm content_manager
microsoft internet_explorer
mozilla firefox
mozilla firefox_esr
mozilla firefox_os
mozilla network_security_services
mozilla seamonkey
mozilla thunderbird
openssl openssl · … → 1.0.1m
openssl openssl · 1.0.1 → 1.0.1m
openssl openssl · 1.0.2 → 1.0.2a
opera opera_browser
oracle jdk
oracle jre
oracle jrockit
oracle sparc-opl_service_processor · … → 1121
suse linux_enterprise_desktop
suse linux_enterprise_server
suse linux_enterprise_software_development_kit
suse suse_linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References