Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.806674
Category:General
Title:OpenSSL 'Diffie-Hellman small subgroups' MitM Attack Vulnerability - Linux
Summary:OpenSSL is prone to a man-in-the-middle (MitM) attack vulnerability.
Description:Summary:
OpenSSL is prone to a man-in-the-middle (MitM) attack vulnerability.

Vulnerability Insight:
The flaw exists as the primes used in X9.42 style
parameter files may not be safe. When an application is using Diffie-Hellman
configured with parameters based on primes that are not safe then an attacker
could use this fact to find a peer's private DH exponent.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to conduct man-in-the-middle attack.

Affected Software/OS:
OpenSSL versions 1.0.2x before 1.0.2f on
Linux.

Solution:
Upgrade to OpenSSL 1.0.2f or later.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-0701
1034849
http://www.securitytracker.com/id/1034849
82233
http://www.securityfocus.com/bid/82233
91787
http://www.securityfocus.com/bid/91787
FEDORA-2016-527018d2ff
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176373.html
GLSA-201601-05
https://security.gentoo.org/glsa/201601-05
USN-2883-1
http://www.ubuntu.com/usn/USN-2883-1
VU#257823
https://www.kb.cert.org/vuls/id/257823
http://intothesymmetry.blogspot.com/2016/01/openssl-key-recovery-attack-on-dh-small.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
http://www.openssl.org/news/secadv/20160128.txt
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=878e2c5b13010329c203f309ed0c8f2113f85648
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=c5b831f21d0d29d1e517d139d9d101763f60c9a2
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_us
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164821
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390893
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
openSUSE-SU-2016:0637
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.