Cryptographic Issues Affecting openssl package, versions >=1.0.200, <1.0.206


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
21.95% (96th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cryptographic Issues vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-COCOAPODS-OPENSSL-471305
  • published2 Oct 2019
  • disclosed31 Dec 2015
  • creditUnknown

Introduced: 31 Dec 2015

CVE-2015-3197  (opens in a new tab)
CWE-200  (opens in a new tab)
CWE-310  (opens in a new tab)

How to fix?

Upgrade OpenSSL to version 1.0.206 or higher.

Overview

OpenSSL is a SSL/TLS and Crypto toolkit. Deprecated in Mac OS and gone in iOS, this spec gives your project non-deprecated OpenSSL support.

Affected versions of this package are vulnerable to Cryptographic Issues. OpenSSL is vulnerable to cipher bypasses. A malicious user can negotiate and complete an SSLv2 handshake with the server even if the ciphers have been disabled on the server. SSLv2 handshakes are vulnerable to man-in-the-middle attacks.

CVSS Base Scores

version 3.1