CVE-2011-3389

CVE-2011-3389

Published · Updated

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 73%
from disclosure to weapon1134 days
Published on NVDSep 6
metasploit+1134d
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (28 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 4 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
Fixed
18 products (610 components)
Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux AS version 4 Extras · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Desktop Supplementary (v. 5) · Red Hat Enterprise Linux ES version 4 Extras · and others 13
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
Affected products
n/a · n/a