CVE-2016-0800
Published · Updated
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 82%
from disclosure to weapon0 days
Published on NVDMar 1
metasploitOct 14
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
6 products
Red Hat Enterprise Linux 5 · Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat JBoss Enterprise Web Server 2 · Red Hat JBoss Enterprise Web Server 3 · and others 1
no_fix_planned: Will not fix
Fixed
43 products (443 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux Server EUS (v. 7.1) · Red Hat Enterprise Linux Server EUS (v. 6.6) · and others 38
Not affected
4 products (14 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 5 · Red Hat JBoss Enterprise Application Platform 5
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
Affected products
n/a · n/aReferences
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10722http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html