CVE-2010-4180
published 2010-12-06CVE-2010-4180: OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
9.50%
94.9th percentile
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 0.9.8k-1 (bookworm) | openssl 0.9.8k-1 (bookworm) |
| debian | openssl | < openssl 0.9.8o-4 (bookworm) | openssl 0.9.8o-4 (bookworm) |
| f5 | nginx | < 0.9.2 | 0.9.2 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openssl | openssl | < 0.9.8q | 0.9.8q |
| openssl | openssl | <= 0.9.8i | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hvp6-pw37-63wh: OpenSSL before 0
ghsa_unreviewed·2022-05-17
CVE-2010-4180 [MEDIUM] GHSA-hvp6-pw37-63wh: OpenSSL before 0
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
GHSA
GHSA-2qf2-98wp-cwm9: OpenSSL before 0
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2008-7270 [MEDIUM] GHSA-2qf2-98wp-cwm9: OpenSSL before 0
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
OSV
CVE-2010-4180: OpenSSL before 0
osv·2010-12-06·CVSS 4.3
CVE-2010-4180 [MEDIUM] CVE-2010-4180: OpenSSL before 0
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
OSV
CVE-2008-7270: OpenSSL before 0
osv·2010-12-06·CVSS 4.3
CVE-2008-7270 [MEDIUM] CVE-2008-7270: OpenSSL before 0
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2010-12-08·CVSS 4.3
CVE-2010-4180 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
It was discovered that an old bug workaround in the SSL/TLS
server code allowed an attacker to modify the stored session cache
ciphersuite. This could possibly allow an attacker to downgrade the
ciphersuite to a weaker one on subsequent connections. (CVE-2010-4180)
It was discovered that an old bug workaround in the SSL/TLS
server code allowed an attacker to modify the stored session cache
ciphersuite. An attacker could possibly take advantage of this to
force the use of a disabled cipher. This vulnerability only affects
the versions of OpenSSL in Ubuntu 6.06 LTS, Ubuntu 8.04 LTS, and
Ubuntu 9.10. (CVE-2008-7270)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
vendor_redhat·2010-12-02·CVSS 4.3
CVE-2010-4180 [MEDIUM] openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Red Hat
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
vendor_redhat·2010-12-02·CVSS 4.3
CVE-2008-7270 [MEDIUM] openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2010-4180: openssl - OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHE...
vendor_debian·2010·CVSS 4.3
CVE-2010-4180 [MEDIUM] CVE-2010-4180: openssl - OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHE...
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Scope: local
bookworm: resolved (fixed in 0.9.8o-4)
bullseye: resolved (fixed in 0.9.8o-4)
forky: resolved (fixed in 0.9.8o-4)
sid: resolved (fixed in 0.9.8o-4)
trixie: resolved (fixed in 0.9.8o-4)
Debian
CVE-2008-7270: openssl - OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, ...
vendor_debian·2008·CVSS 4.3
CVE-2008-7270 [MEDIUM] CVE-2008-7270: openssl - OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, ...
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Scope: local
bookworm: resolved (fixed in 0.9.8k-1)
bullseye: resolved (fixed in 0.9.8k-1)
forky: resolved (fixed in 0.9.8k-1)
sid: resolved (fixed in 0.9.8k-1)
trixie: resolved (fixed in 0.9.8k-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-7270 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
bugzilla·2010-12-07·CVSS 4.3
CVE-2008-7270 [MEDIUM] CVE-2008-7270 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
CVE-2008-7270 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-7270 to
the following vulnerability:
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
References:
http://cvs.openssl.org/chngview?cn=17489
https://bugzilla.redhat.com/show_bug.cgi?id=659462
Discussion:
(In reply to comment #0)
> a different vulnerability than CVE-2010-4180.
While CVE description lists these vulnerabilities as dif
Bugzilla
CVE-2010-4180 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
bugzilla·2010-12-02·CVSS 4.3
CVE-2010-4180 [MEDIUM] CVE-2010-4180 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
CVE-2010-4180 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack
Quoting OpenSSL security advisory:
http://openssl.org/news/secadv_20101202.txt
A flaw has been found in the OpenSSL SSL/TLS server code where an old bug
workaround allows malicous clients to modify the stored session cache
ciphersuite. In some cases the ciphersuite can be downgraded to a weaker one
on subsequent connections.
Problem affects SSL/TLS server that enable workaround for old Netscape server SSL implementation bug - SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG. An attacker able to sniff session identifier (sent in plain during the SSL handshake) could use this flaw to force change of the cipher suite in stored session. Client, that later resumes that session, may start using different (weaker) cip
http://cvs.openssl.org/chngview?cn=20131http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052027.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052315.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://marc.info/?l=bugtraq&m=129916880600544&w=2http://marc.info/?l=bugtraq&m=130497251507577&w=2http://marc.info/?l=bugtraq&m=132077688910227&w=2http://openssl.org/news/secadv_20101202.txthttp://osvdb.org/69565http://secunia.com/advisories/42469http://secunia.com/advisories/42473http://secunia.com/advisories/42493http://secunia.com/advisories/42571http://secunia.com/advisories/42620http://secunia.com/advisories/42811http://secunia.com/advisories/42877http://secunia.com/advisories/43169http://secunia.com/advisories/43170http://secunia.com/advisories/43171http://secunia.com/advisories/43172http://secunia.com/advisories/43173http://secunia.com/advisories/44269http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471http://support.apple.com/kb/HT4723http://ubuntu.com/usn/usn-1029-1http://www.debian.org/security/2011/dsa-2141http://www.kb.cert.org/vuls/id/737740http://www.mandriva.com/security/advisories?name=MDVSA-2010:248http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0978.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0979.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/archive/1/522176http://www.securityfocus.com/bid/45164http://www.securitytracker.com/id?1024822http://www.vupen.com/english/advisories/2010/3120http://www.vupen.com/english/advisories/2010/3122http://www.vupen.com/english/advisories/2010/3134http://www.vupen.com/english/advisories/2010/3188http://www.vupen.com/english/advisories/2011/0032http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0268https://bugzilla.redhat.com/show_bug.cgi?id=659462https://kb.bluecoat.com/index?page=content&id=SA53&actp=LISThttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18910http://cvs.openssl.org/chngview?cn=20131http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052027.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052315.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://marc.info/?l=bugtraq&m=129916880600544&w=2http://marc.info/?l=bugtraq&m=130497251507577&w=2http://marc.info/?l=bugtraq&m=132077688910227&w=2http://openssl.org/news/secadv_20101202.txthttp://osvdb.org/69565http://secunia.com/advisories/42469http://secunia.com/advisories/42473http://secunia.com/advisories/42493http://secunia.com/advisories/42571http://secunia.com/advisories/42620http://secunia.com/advisories/42811http://secunia.com/advisories/42877http://secunia.com/advisories/43169http://secunia.com/advisories/43170http://secunia.com/advisories/43171http://secunia.com/advisories/43172http://secunia.com/advisories/43173http://secunia.com/advisories/44269http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471http://support.apple.com/kb/HT4723http://ubuntu.com/usn/usn-1029-1http://www.debian.org/security/2011/dsa-2141http://www.kb.cert.org/vuls/id/737740http://www.mandriva.com/security/advisories?name=MDVSA-2010:248http://www.redhat.com/support/errata/RHSA-2010-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0978.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0979.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.securityfocus.com/archive/1/522176http://www.securityfocus.com/bid/45164http://www.securitytracker.com/id?1024822http://www.vupen.com/english/advisories/2010/3120http://www.vupen.com/english/advisories/2010/3122http://www.vupen.com/english/advisories/2010/3134http://www.vupen.com/english/advisories/2010/3188http://www.vupen.com/english/advisories/2011/0032http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0268https://bugzilla.redhat.com/show_bug.cgi?id=659462https://kb.bluecoat.com/index?page=content&id=SA53&actp=LISThttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18910
2010-12-06
Published