Oval Definition:oval:org.mitre.oval:def:8535
Revision Date:2015-04-20Version:28
Title:HP-UX Running OpenSSL, Remote Unauthorized Data Injection, Denial of Service (DoS)
Description:The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-3555
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX02482
  • HP-UX B.11.23
  • AND filesets tests
  • openssl.OPENSSL-PVT version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-RUN version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-CER version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-CONF version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-DOC version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-INC version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-LIB version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-MAN version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-MIS version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-SRC version is less than A.00.09.08l.002
  • OR openssl.OPENSSL-PRNG version is less than A.00.09.08l.002
  • OR Criteria meets HP Security Bulletin HPSBUX02482
  • HP-UX B.11.11
  • AND filesets tests
  • openssl.OPENSSL-PVT version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-RUN version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-CER version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-CONF version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-DOC version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-INC version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-LIB version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-MAN version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-SRC version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-MIS version is less than A.00.09.08l.001
  • OR openssl.OPENSSL-PRNG version is less than A.00.09.08l.001
  • OR Criteria meets HP Security Bulletin HPSBUX02482
  • HP-UX B.11.31
  • AND filesets tests
  • openssl.OPENSSL-PRNG version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-RUN version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-CER version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-CONF version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-DOC version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-INC version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-LIB version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-MAN version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-SRC version is less than A.00.09.08l.003
  • OR openssl.OPENSSL-MIS version is less than A.00.09.08l.003
  • BACK