TROYANOSYVIRUS
Voltar para CVEs

CVE-2015-4000

N/A

Descricao

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado5/21/2015
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

apple:iphone_osapple:mac_os_xapple:safaricanonical:ubuntu_linuxdebian:debian_linuxgoogle:chromehp:hp-uxibm:content_managermicrosoft:internet_explorermozilla:firefoxmozilla:firefox_esrmozilla:firefox_osmozilla:network_security_servicesmozilla:seamonkeymozilla:thunderbirdopenssl:opensslopera:opera_browseroracle:jdkoracle:jreoracle:jrockitoracle:sparc-opl_service_processorsuse:linux_enterprise_desktopsuse:linux_enterprise_serversuse:linux_enterprise_software_development_kitsuse:suse_linux_enterprise_server

Fraquezas (CWE)

CWE-310

Referencias

https://weakdh.org/(cve@mitre.org)
http://marc.info/?l=bugtraq&m=143506486712441&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143557934009303&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143558092609708&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143628304012255&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143637549705650&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143655800220052&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143880121627664&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144043644216842&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144050121701297&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144060576831314&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144060606031437&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144061542602287&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144069189622016&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144102017024820&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144104533800819&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144493176821532&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=145409266329539&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2015/05/20/8(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1072.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1185.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1197.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1228.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1229.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1230.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1241.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1242.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1243.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1485.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1486.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1488.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1526.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1544.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1604.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2016-1624.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2016-2056.html(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT204941(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT204942(af854a3a-2127-422b-91ae-364da2661108)
http://support.citrix.com/article/CTX201114(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959111(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959195(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959325(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959453(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959481(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959517(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959530(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959539(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959636(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21959812(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21960191(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21961717(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21962455(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21962739(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3287(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3300(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3316(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3324(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3339(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2016/dsa-3688(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/74733(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/91787(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032474(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032475(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032476(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032637(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032645(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032647(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032648(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032649(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032650(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032651(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032652(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032653(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032654(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032655(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032656(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032688(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032699(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032702(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032727(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032759(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032777(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032778(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032783(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032784(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032856(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032864(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032865(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032871(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032884(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032910(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032932(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1032960(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033019(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033064(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033065(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033067(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033208(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033209(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033210(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033222(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033341(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033385(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033416(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033430(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033433(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033513(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033760(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033891(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1033991(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1034087(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1034728(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1034884(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1036218(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1040630(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2656-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2656-2(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2673-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2696-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2706-1(af854a3a-2127-422b-91ae-364da2661108)
https://bto.bluecoat.com/security-advisory/sa98(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1138554(af854a3a-2127-422b-91ae-364da2661108)
https://openssl.org/news/secadv/20150611.txt(af854a3a-2127-422b-91ae-364da2661108)
https://puppet.com/security/cve/CVE-2015-4000(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201506-02(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201512-10(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201603-11(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201701-46(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20150619-0001/(af854a3a-2127-422b-91ae-364da2661108)
https://support.citrix.com/article/CTX216642(af854a3a-2127-422b-91ae-364da2661108)
https://weakdh.org/(af854a3a-2127-422b-91ae-364da2661108)
https://weakdh.org/imperfect-forward-secrecy.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.openssl.org/news/secadv_20150611.txt(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.suse.com/security/cve/CVE-2015-4000.html(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.