Oval Definition:oval:org.mitre.oval:def:20828
Revision Date:2014-01-20Version:15
Title:Multiple OpenSSL vulnerabilities
Description:OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-4180
Platform(s):IBM AIX 6.1
IBM AIX 7.1
Product(s):
Definition Synopsis
  • platforms
  • IBM AIX 6.1 is installed
  • OR IBM AIX 7.1 is installed
  • AND filesets
  • openssl.base less than 0.9.8.1301
  • OR OpenSSL-fips.base less than 12.9.8.1301
  • BACK