CVE-2008-7270
published 2010-12-06CVE-2008-7270: OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.43%
87.7th percentile
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8k-1 (bookworm) | openssl 0.9.8k-1 (bookworm) |
| openssl | openssl | <= 0.9.8i | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2010-12-08·CVSS 4.3
CVE-2010-4180 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
It was discovered that an old bug workaround in the SSL/TLS
server code allowed an attacker to modify the stored session cache
ciphersuite. This could possibly allow an attacker to downgrade the
ciphersuite to a weaker one on subsequent connections. (CVE-2010-4180)
It was discovered that an old bug workaround in the SSL/TLS
server code allowed an attacker to modify the stored session cache
ciphersuite. An attacker could possibly take advantage of this to
force the use of a disabled cipher. This vulnerability only affects
the versions of OpenSSL in Ubuntu 6.06 LTS, Ubuntu 8.04 LTS, and
Ubuntu 9.10. (CVE-2008-7270)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
vendor_redhat·2010-12-02·CVSS 4.3
CVE-2008-7270 [MEDIUM] openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2008-7270: openssl - OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, ...
vendor_debian·2008·CVSS 4.3
CVE-2008-7270 [MEDIUM] CVE-2008-7270: openssl - OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, ...
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Scope: local
bookworm: resolved (fixed in 0.9.8k-1)
bullseye: resolved (fixed in 0.9.8k-1)
forky: resolved (fixed in 0.9.8k-1)
sid: resolved (fixed in 0.9.8k-1)
trixie: resolved (fixed in 0.9.8k-1)
GHSA
GHSA-2qf2-98wp-cwm9: OpenSSL before 0
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2008-7270 [MEDIUM] GHSA-2qf2-98wp-cwm9: OpenSSL before 0
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
OSV
CVE-2008-7270: OpenSSL before 0
osv·2010-12-06·CVSS 4.3
CVE-2008-7270 [MEDIUM] CVE-2008-7270: OpenSSL before 0
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
No detection rules found.
No public exploits indexed.
http://cvs.openssl.org/chngview?cn=17489http://marc.info/?l=bugtraq&m=132077688910227&w=2http://secunia.com/advisories/42493http://ubuntu.com/usn/usn-1029-1http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0978.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/archive/1/522176http://www.securityfocus.com/bid/45254https://bugzilla.redhat.com/show_bug.cgi?id=659462http://cvs.openssl.org/chngview?cn=17489http://marc.info/?l=bugtraq&m=132077688910227&w=2http://secunia.com/advisories/42493http://ubuntu.com/usn/usn-1029-1http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0978.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/archive/1/522176http://www.securityfocus.com/bid/45254https://bugzilla.redhat.com/show_bug.cgi?id=659462
2010-12-06
Published