|
|
Log in / Subscribe / Register

openssl: two vulnerabilities

Package(s):openssl CVE #(s):CVE-2016-0703 CVE-2016-0704
Created:March 2, 2016 Updated:March 2, 2016
Description: From the Red Hat advisory:

It was discovered that the SSLv2 servers using OpenSSL accepted SSLv2 connection handshakes that indicated non-zero clear key length for non-export cipher suites. An attacker could use this flaw to decrypt recorded SSLv2 sessions with the server by using it as a decryption oracle.(CVE-2016-0703)

It was discovered that the SSLv2 protocol implementation in OpenSSL did not properly implement the Bleichenbacher protection for export cipher suites. An attacker could use a SSLv2 server using OpenSSL as a Bleichenbacher oracle. (CVE-2016-0704)

Alerts:
SUSE SUSE-SU-2016:1057-1 openssl 2016-04-15
Gentoo 201603-15 openssl 2016-03-20
SUSE SUSE-SU-2016:0786-1 sles12-docker-image 2016-03-16
SUSE SUSE-SU-2016:0778-1 sles11sp4-docker-image 2016-03-15
SUSE SUSE-SU-2016:0748-1 sles12sp1-docker-image 2016-03-14
openSUSE openSUSE-SU-2016:0720-1 openssl 2016-03-11
Scientific Linux SLSA-2016:0372-1 openssl098e 2016-03-09
CentOS CESA-2016:0372 openssl098e 2016-03-09
CentOS CESA-2016:0372 openssl098e 2016-03-09
Red Hat RHSA-2016:0372-01 openssl098e 2016-03-09
SUSE SUSE-SU-2016:0678-1 OpenSSL 2016-03-07
SUSE SUSE-SU-2016:0641-1 openssl 2016-03-03
SUSE SUSE-SU-2016:0631-1 compat-openssl097g 2016-03-02
openSUSE openSUSE-SU-2016:0638-1 openssl 2016-03-02
openSUSE openSUSE-SU-2016:0637-1 openssl 2016-03-02
SUSE SUSE-SU-2016:0621-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0624-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0617-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0620-1 openssl 2016-03-01
openSUSE openSUSE-SU-2016:0628-1 openssl 2016-03-02
Red Hat RHSA-2016:0306-01 openssl 2016-03-01
Red Hat RHSA-2016:0304-01 openssl 2016-03-01
Red Hat RHSA-2016:0303-01 openssl 2016-03-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds