← volver
CVE-2011-3389

CVE-2011-3389

40Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 73%
de la publicación al arma1134 días
Publicada en NVD6 sept
metasploit+1134d
probabilidad de explotación
73%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
3 productos (28 componentes)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 4 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
Corregido
18 productos (610 componentes)
Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux AS version 4 Extras · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Desktop Supplementary (v. 5) · Red Hat Enterprise Linux ES version 4 Extras · y otros 13
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
Productos afectados
n/a · n/a