CVE-2005-2969
published 2005-10-18CVE-2005-2969: The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.87%
91.1th percentile
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8-3 (bookworm) | openssl 0.9.8-3 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8-3 | 0.9.8-3 |
| openssl | openssl | >= 0 < 0.9.8-3 | 0.9.8-3 |
| openssl | openssl | >= 0 < 0.9.8-3 | 0.9.8-3 |
| openssl | openssl | >= 0 < 0.9.8-3 | 0.9.8-3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_cisco7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
SSL library vulnerability
vendor_ubuntu·2005-10-14
CVE-2005-2969 SSL library vulnerability
Title: SSL library vulnerability
Summary: SSL library vulnerability
Yutaka Oiwa discovered a possible cryptographic weakness in OpenSSL
applications. Applications using the OpenSSL library can use the
SSL_OP_MSIE_SSLV2_RSA_PADDING option (or SSL_OP_ALL, which implies the
former) to maintain compatibility with third party products, which is
achieved by working around known bugs in them.
The SSL_OP_MSIE_SSLV2_RSA_PADDING option disabled a verification step
in the SSL 2.0 server supposed to prevent active protocol-version
rollback attacks. With this verification step disabled, an attacker
acting as a "machine-in-the-middle" could force a client and a server to
negotiate the SSL 2.0 protocol even if these parties both supported
SSL 3.0 or TLS 1.0. The SSL 2.0 protocol is known to have sever
Cisco
OpenSSL Version Rollback and Weak Cryptographic Algorithm Vulnerabilities
vendor_cisco·2005-10-12·CVSS 7.5
CVE-2005-2969 [HIGH] OpenSSL Version Rollback and Weak Cryptographic Algorithm Vulnerabilities
OpenSSL Version Rollback and Weak Cryptographic Algorithm Vulnerabilities
OpenSSL contains vulnerabilities that could allow an unauthenticated, remote attacker to bypass security restrictions.
The first vulnerability (CVE-2005-2969) affects any application using a SL/TLS server implementation provided by OpenSSL versions 0.9.7g and prior. If these implementations have options designed to mitigate third party bugs enabled, a remote attacker conducting a man-in-the-middle attack could force connections between the hosts to use the 2.0 version of the SSL protocol. A known cryptographic weaknesses exists in the SSL 2.0 protocol.
The second vulnerability (CVE-2005-2946) exists in the default configuration of OpenSSL versions prior to 0.9.8a. This configuration creates message digests using MD5
Red Hat
openssl mitm downgrade attack
vendor_redhat·2005-10-11·CVSS 5.0
CVE-2005-2969 [MEDIUM] openssl mitm downgrade attack
openssl mitm downgrade attack
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-2969: openssl - The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 befor...
vendor_debian·2005·CVSS 5.0
CVE-2005-2969 [MEDIUM] CVE-2005-2969: openssl - The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 befor...
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 0.9.8-3)
bullseye: resolved (fixed in 0.9.8-3)
forky: resolved (fixed in 0.9.8-3)
sid: resolved (fixed in 0.9.8-3)
trixie: resolved (fixed in 0.9.8-3)
GHSA
GHSA-h7wj-q4wv-chfq: The SSL/TLS server implementation in OpenSSL 0
ghsa_unreviewed·2022-05-03
CVE-2005-2969 [MEDIUM] GHSA-h7wj-q4wv-chfq: The SSL/TLS server implementation in OpenSSL 0
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
OSV
CVE-2005-2969: The SSL/TLS server implementation in OpenSSL 0
osv·2005-10-18·CVSS 5.0
CVE-2005-2969 [MEDIUM] CVE-2005-2969: The SSL/TLS server implementation in OpenSSL 0
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2969 openssl mitm downgrade attack
bugzilla·2008-01-29·CVSS 5.0
CVE-2005-2969 [MEDIUM] CVE-2005-2969 openssl mitm downgrade attack
CVE-2005-2969 openssl mitm downgrade attack
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-2969 to the following vulnerability:
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
References:
http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754
http://www.juniper.net/support/security/alerts/PSN-2005-12-025.txt
ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers/dir5.10.3_docs_relnotes.pdf
http://www.openssl.org/news/secadv_20051011.txt
http
Bugzilla
CVE-2005-2969 openssl mitm downgrade attack
bugzilla·2008-01-29·CVSS 5.0
CVE-2005-2969 [MEDIUM] CVE-2005-2969 openssl mitm downgrade attack
CVE-2005-2969 openssl mitm downgrade attack
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-2969 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations.
References:
http://www.securityfocus.com/archive/1/archive/1/436640/100/0/threaded
http://www.securityfocus.com/bid/18483
http://www.frsirt.com/english/advisories/2006/2310
http://secunia.com/advisories/20607
http://securityreason.com/securityalert/1091
http://xforce.iss.net/xforce/xfdb/27154
Discussion:
mistake
ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers/dir5.10.3_docs_relnotes.pdfhttp://docs.info.apple.com/article.html?artnum=302847http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://secunia.com/advisories/17146http://secunia.com/advisories/17151http://secunia.com/advisories/17153http://secunia.com/advisories/17169http://secunia.com/advisories/17178http://secunia.com/advisories/17180http://secunia.com/advisories/17189http://secunia.com/advisories/17191http://secunia.com/advisories/17210http://secunia.com/advisories/17259http://secunia.com/advisories/17288http://secunia.com/advisories/17335http://secunia.com/advisories/17344http://secunia.com/advisories/17389http://secunia.com/advisories/17409http://secunia.com/advisories/17432http://secunia.com/advisories/17466http://secunia.com/advisories/17589http://secunia.com/advisories/17617http://secunia.com/advisories/17632http://secunia.com/advisories/17813http://secunia.com/advisories/17888http://secunia.com/advisories/18045http://secunia.com/advisories/18123http://secunia.com/advisories/18165http://secunia.com/advisories/18663http://secunia.com/advisories/19185http://secunia.com/advisories/21827http://secunia.com/advisories/23280http://secunia.com/advisories/23340http://secunia.com/advisories/23843http://secunia.com/advisories/23915http://secunia.com/advisories/25973http://secunia.com/advisories/26893http://secunia.com/advisories/31492http://securitytracker.com/id?1015032http://sunsolve.sun.com/search/document.do?assetkey=1-26-101974-1http://support.avaya.com/elmodocs2/security/ASA-2006-031.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-260.htmhttp://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754http://www.cisco.com/warp/public/707/cisco-response-20051202-openssl.shtmlhttp://www.debian.org/security/2005/dsa-875http://www.debian.org/security/2005/dsa-881http://www.debian.org/security/2005/dsa-882http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.htmlhttp://www.hitachi-support.com/security_e/vuls_e/HS07-016_e/index-e.htmlhttp://www.juniper.net/support/security/alerts/PSN-2005-12-025.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2005:179http://www.novell.com/linux/security/advisories/2005_61_openssl.htmlhttp://www.openssl.org/news/secadv_20051011.txthttp://www.redhat.com/support/errata/RHSA-2005-762.htmlhttp://www.redhat.com/support/errata/RHSA-2005-800.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0629.htmlhttp://www.securityfocus.com/bid/15071http://www.securityfocus.com/bid/15647http://www.securityfocus.com/bid/24799http://www.vupen.com/english/advisories/2005/2036http://www.vupen.com/english/advisories/2005/2659http://www.vupen.com/english/advisories/2005/2710http://www.vupen.com/english/advisories/2005/2908http://www.vupen.com/english/advisories/2005/3002http://www.vupen.com/english/advisories/2005/3056http://www.vupen.com/english/advisories/2006/3531http://www.vupen.com/english/advisories/2007/0326http://www.vupen.com/english/advisories/2007/0343http://www.vupen.com/english/advisories/2007/2457https://exchange.xforce.ibmcloud.com/vulnerabilities/35287https://issues.rpath.com/browse/RPL-1633https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11454ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers/dir5.10.3_docs_relnotes.pdfhttp://docs.info.apple.com/article.html?artnum=302847http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://secunia.com/advisories/17146http://secunia.com/advisories/17151http://secunia.com/advisories/17153http://secunia.com/advisories/17169http://secunia.com/advisories/17178http://secunia.com/advisories/17180http://secunia.com/advisories/17189http://secunia.com/advisories/17191http://secunia.com/advisories/17210http://secunia.com/advisories/17259http://secunia.com/advisories/17288http://secunia.com/advisories/17335http://secunia.com/advisories/17344http://secunia.com/advisories/17389http://secunia.com/advisories/17409http://secunia.com/advisories/17432http://secunia.com/advisories/17466http://secunia.com/advisories/17589http://secunia.com/advisories/17617http://secunia.com/advisories/17632http://secunia.com/advisories/17813
+ 48 more references
2005-10-18
Published