Cryptographic Issues Affecting openssl package, versions >=1.0.200, <1.0.206
Snyk CVSS
Attack Complexity
High
Confidentiality
High
Threat Intelligence
EPSS
2.43% (89th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-COCOAPODS-OPENSSL-471305
- published 2 Oct 2019
- disclosed 31 Dec 2015
- credit Unknown
How to fix?
Upgrade OpenSSL
to version 1.0.206 or higher.
Overview
OpenSSL is a SSL/TLS and Crypto toolkit. Deprecated in Mac OS and gone in iOS, this spec gives your project non-deprecated OpenSSL support.
Affected versions of this package are vulnerable to Cryptographic Issues. OpenSSL is vulnerable to cipher bypasses. A malicious user can negotiate and complete an SSLv2 handshake with the server even if the ciphers have been disabled on the server. SSLv2 handshakes are vulnerable to man-in-the-middle attacks.
References
- Cert Vulnerability Note
- Fedora Security Announcement
- Gentoo Security Advisory
- HPE Support Center Security Bulletin
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- https://git.openssl.org/?p=openssl.git;a=commit;h=d81a1600588b726c2bdccda7efad3cc7a87d6245
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_us
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:11.openssl.asc
- OpenSSL Security Advisory
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Bulletin
- Oracle Security Bulletin
- Oracle Security Bulletin
- Security Focus
- Security Focus
- Security Tracker