Oval Definition:
oval:org.cisecurity:def:749
Revision Date
:
2016-07-01
Version
:
13
Title
:
Multiple vulnerabilities in OpenSSL affect AIX
Description
:
A cross-protocol attack was discovered that could lead to decryption of TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites as a Bleichenbacher RSA padding oracle. This vulnerability is known as DROWN
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2016-0800
Platform(s)
:
IBM AIX 6.1
IBM AIX 7.1
Product(s)
:
Definition Synopsis
platforms
IBM AIX 6.1 is installed
OR
IBM AIX 7.1 is installed
AND
filesets
File Version Exists
openssl.base greater than or equal 1.0.1.500
AND
openssl.base less than or equal 1.0.1.515
AND
NOT
Interim fix IV83169m9a (vuid: 00F850C34C00040104041816) is installed
OR
File Version Exists
openssl.base greater than or equal 0.9.8.401
AND
openssl.base less than or equal 0.9.8.2506
AND
NOT
Interim fix IV83169m9b (vuid: 00F850C34C00040104040816) is installed
OR
File Version Exists
openssl.base equal to 1.0.2.500
AND
NOT
Interim fix IV83169s9d (vuid: 00F850C34C00040105042616) is installed
OR
File Version Exists
openssl.base greater than or equal 12.9.8.1100
AND
openssl.base less than or equal 12.9.8.2506
AND
NOT
Interim fix IV83169m9c (vuid: 00F850C34C00040110042716) is installed
BACK