CVE-2016-0800
Publicada el · Actualizada el
40Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 82%
de la publicación al arma0 días
Publicada en NVD1 mar
metasploit14 oct
probabilidad de explotación
82%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Afectado
6 productos
Red Hat Enterprise Linux 5 · Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat JBoss Enterprise Web Server 2 · Red Hat JBoss Enterprise Web Server 3 · y otros 1
no_fix_planned: Will not fix
Corregido
43 productos (443 componentes)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux Server EUS (v. 7.1) · Red Hat Enterprise Linux Server EUS (v. 6.6) · y otros 38
No afectado
4 productos (14 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 5 · Red Hat JBoss Enterprise Application Platform 5
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
Productos afectados
n/a · n/aReferencias
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10722http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html