CVE-2011-5095
published 2012-06-20CVE-2011-5095: The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it…
PriorityP417medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.09%
79.5th percentile
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8a-1 (bookworm) | openssl 0.9.8a-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8a-1 | 0.9.8a-1 |
| openssl | openssl | >= 0 < 0.9.8a-1 | 0.9.8a-1 |
| openssl | openssl | >= 0 < 0.9.8a-1 | 0.9.8a-1 |
| openssl | openssl | >= 0 < 0.9.8a-1 | 0.9.8a-1 |
| polarssl | polarssl | <= 0.14.0 | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhj2-g5qf-66wr: The Diffie-Hellman key-exchange implementation in OpenSSL 0
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2011-5095 [MEDIUM] GHSA-xhj2-g5qf-66wr: The Diffie-Hellman key-exchange implementation in OpenSSL 0
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
GHSA
GHSA-rwm6-hmj6-r6h5: The Diffie-Hellman key-exchange implementation in dhm
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2011-1923 [MEDIUM] GHSA-rwm6-hmj6-r6h5: The Diffie-Hellman key-exchange implementation in dhm
The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095.
OSV
CVE-2011-5095: The Diffie-Hellman key-exchange implementation in OpenSSL 0
osv·2012-06-20·CVSS 4.0
CVE-2011-5095 [MEDIUM] CVE-2011-5095: The Diffie-Hellman key-exchange implementation in OpenSSL 0
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
Red Hat
openssl: weak public value accepted during Diffie Hellman key exchange
vendor_redhat·2011-04-13·CVSS 4.0
CVE-2011-5095 [MEDIUM] openssl: weak public value accepted during Diffie Hellman key exchange
openssl: weak public value accepted during Diffie Hellman key exchange
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
Statement: This issue was addressed in Red Hat Enterprise Linux 5 openssl packages via RHBA-2011:1010, bug 698175. It did not affect openssl packages shipped with Red Hat Enterprise Linux 6.
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Will
Debian
CVE-2011-5095: openssl - The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode ...
vendor_debian·2011·CVSS 4.0
CVE-2011-5095 [MEDIUM] CVE-2011-5095: openssl - The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode ...
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
Scope: local
bookworm: resolved (fixed in 0.9.8a-1)
bullseye: resolved (fixed in 0.9.8a-1)
forky: resolved (fixed in 0.9.8a-1)
sid: resolved (fixed in 0.9.8a-1)
trixie: resolved (fixed in 0.9.8a-1)
No detection rules found.
No public exploits indexed.
http://www.cl.cam.ac.uk/~rja14/Papers/psandqs.pdfhttp://www.nessus.org/plugins/index.php?view=single&id=53360https://discussions.nessus.org/thread/3381http://www.cl.cam.ac.uk/~rja14/Papers/psandqs.pdfhttp://www.nessus.org/plugins/index.php?view=single&id=53360https://discussions.nessus.org/thread/3381
2012-06-20
Published