CVE-2015-3197
published 2016-02-15CVE-2015-3197: ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle…
PriorityP335medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
10.73%
95.3th percentile
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products | — | — |
| debian | openssl | < openssl 1.0.0c-2 (bookworm) | openssl 1.0.0c-2 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
BSD
FreeBSD-SA-16:11.openssl: OpenSSL SSLv2 ciphersuite downgrade vulnerability
bsd_advisories·2016-01-30·CVSS 5.9
CVE-2015-3197 [MEDIUM] FreeBSD-SA-16:11.openssl: OpenSSL SSLv2 ciphersuite downgrade vulnerability
FreeBSD-SA-16:11.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL SSLv2 ciphersuite downgrade vulnerability
Category: contrib
Module: openssl
Announced: 2016-01-30
Affects: All supported versions of FreeBSD.
Corrected: 2016-01-28 21:42:10 UTC (stable/10, 10.2-STABLE)
2016-01-30 06:12:03 UTC (releng/10.2, 10.2-RELEASE-p12)
2016-01-30 06:12:03 UTC (releng/10.1, 10.1-RELEASE-p29)
2016-01-30 06:09:38 UTC (stable/9, 9.3-STABLE)
2016-01-30 06:12:03 UTC (releng/9.3, 9.3-RELEASE-p36)
CVE Name: CVE-2015-3197
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collaborative effo
Cisco
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
vendor_cisco·2016-01-29
CVE-2015-3197 [HIGH] Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
On January 28, 2016, the OpenSSL Project released a security advisory detailing two vulnerabilities.
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks on an SSL/TLS connection.
This advisory will be updated as additional information becomes available.
Cisco will release software updates that address these vulnerabilities.
Workarounds that address these vulnerabilities are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160129-openssl
Red Hat
OpenSSL: SSLv2 doesn't block disabled ciphers
vendor_redhat·2016-01-28·CVSS 5.9
CVE-2015-3197 [MEDIUM] OpenSSL: SSLv2 doesn't block disabled ciphers
OpenSSL: SSLv2 doesn't block disabled ciphers
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
A flaw was found in the way malicious SSLv2 clients could negotiate SSLv2 ciphers that were disabled on the server. This could result in weak SSLv2 ciphers being used for SSLv2 connections, making them vulnerable to man-in-the-middle attacks.
Statement: This security flaw can only be exploited when a malicious client negotiates SSLv2 ciphers and completes a SSLv2 handshake. This flaw cannot be actively exploited by a Man-I
Debian
CVE-2015-3197: openssl - ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not pr...
vendor_debian·2015·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197: openssl - ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not pr...
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
Scope: local
bookworm: resolved (fixed in 1.0.0c-2)
bullseye: resolved (fixed in 1.0.0c-2)
forky: resolved (fixed in 1.0.0c-2)
sid: resolved (fixed in 1.0.0c-2)
trixie: resolved (fixed in 1.0.0c-2)
Cisco
Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
vendor_cisco
CVE-2015-3197 Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
CVE-2015-3197: Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
On January 28, 2016, the OpenSSL Project released a security advisory detailing two vulnerabilities. Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks on an SSL/TLS connection. This advisory will be updated as additional information becomes available. Cisco will release software updates that address these vulnerabilities.
Bug IDs: CSCuy07208, CSCuy07223, CSCuy07225, CSCuy07208, CSCuy07223
GHSA
GHSA-7cfp-xp7x-9xqq: ssl/s2_srvr
ghsa_unreviewed·2022-05-17
CVE-2015-3197 [MEDIUM] CWE-200 GHSA-7cfp-xp7x-9xqq: ssl/s2_srvr
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
OSV
CVE-2015-3197: ssl/s2_srvr
osv·2016-02-15·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197: ssl/s2_srvr
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
No detection rules found.
No public exploits indexed.
Tenable
New Scan Policies, Plugins and Dashboard for CVE-2016-0800: DROWN
blogs_tenable·2016-03-07·CVSS 5.9
[MEDIUM] New Scan Policies, Plugins and Dashboard for CVE-2016-0800: DROWN
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
New Scan Policies, Plugins and Dashboard for CVE-2016-0800: DROWN
blogs_tenable·2016-03-07·CVSS 5.9
CVE-2016-0800 [MEDIUM] New Scan Policies, Plugins and Dashboard for CVE-2016-0800: DROWN
Blog /
Subscribe
# New Scan Policies, Plugins and Dashboard for CVE-2016-0800: DROWN
Kelly Prevett
March 7, 2016
3 Min Read
No matter which product you have, Nessus®, SecurityCenter™, SecurityCenter CV™, or Passive Vulnerability Scanner™, Tenable can determine if you are at risk of “drowning.”
The DROWN CVE-2016-0800 vulnerability is a cross protocol vulnerability that enables an attacker to decrypt TLS connections between up-to-date clients and servers by sending packets to any server that supports SSLv2 using the same private key.
The DROWN vulnerability’s impact is made worse by two additional OpenSSL implementation vulnerabilities:
- CVE-2015-3197, which allows a DROWN attacker to connect to the server with disabled SSLv2 ciphersuites, provided that support for SSLv2 itself is
Qualys
SSL Labs DROWN Test Implementation Details | Qualys
blogs_qualys·2016-03-04·CVSS 5.9
[MEDIUM] SSL Labs DROWN Test Implementation Details | Qualys
Two days ago the DROWN vulnerability came to light , showing new ways to attack TLS. SSL Labs deployed tests for DROWN in the staging environment yesterday, and we’ll be pushing it to production shortly. Because DROWN is a tricky problem, the aim of this blog post is to provide an explanation of what we test for and how exactly.
First of all, we have known SSL v2 to be insecure for a very long time—over 20 years. As a result, even before DROWN SSL Labs used to give Fs to servers that supported this ancient version of the SSL protocol. DROWN actually makes things worse, because it abuses SSL v2 to attack all other protocols.
Further, DROWN introduces two additional attack vectors:
A server that has SSL v2 enabled can be used to attack any other servers that reuse the same RSA key; even t
Qualys
SSL Labs DROWN Test Implementation Details | Qualys
blogs_qualys·2016-03-04·CVSS 5.9
[MEDIUM] SSL Labs DROWN Test Implementation Details | Qualys
Two days ago the DROWN vulnerability came to light, showing new ways to attack TLS. SSL Labs deployed tests for DROWN in the staging environment yesterday, and we’ll be pushing it to production shortly. Because DROWN is a tricky problem, the aim of this blog post is to provide an explanation of what we test for and how exactly.
First of all, we have known SSL v2 to be insecure for a very long time—over 20 years. As a result, even before DROWN SSL Labs used to give Fs to servers that supported this ancient version of the SSL protocol. DROWN actually makes things worse, because it abuses SSL v2 to attack all other protocols.
Further, DROWN introduces two additional attack vectors:
- A server that has SSL v2 enabled can be used to attack any other servers that reuse the same RSA key; even
HackerOne
Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)
hackerone·2016-09-21·CVSS 5.9
CVE-2016-0800 [MEDIUM] Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)
Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)
General DROWN was responsibly disclosed to the OpenSSL team prior to the public disclosure.
This OpenSSL blog post, by Viktor Dukhovni and Emilia Käsper, describes the vulnerability:
https://www.openssl.org/blog/blog/2016/03/01/an-openssl-users-guide-to-drown/
This is probably a good opportunity to again thank everyone who helped with the disclosure process :-)
Severity: High
A cross-protocol attack was discovered that could lead to decryption of TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites as a Bleichenbacher RSA padding oracle. Note that traffic between clients and non-vulnerable servers can be decrypted provided another server supporting SSLv2 and EXPORT ciphers (even with a different protoc
HackerOne
SSLv2 doesn't block disabled ciphers (CVE-2015-3197)
hackerone·2016-09-21·CVSS 5.9
CVE-2015-3197 [MEDIUM] SSLv2 doesn't block disabled ciphers (CVE-2015-3197)
SSLv2 doesn't block disabled ciphers (CVE-2015-3197)
This is a DROWN-related issue that essentially circumvented the instructions on how to disable SSLv2 at the time. Its primary effect was that a lot of servers were vulnerable to DROWN even though they thought they had SSLv2 disabled.
It was reported to OpenSSL and fixed in versions 1.0.2f and 1.0.1r:
https://www.openssl.org/news/secadv/20160128.txt
(and obviously the DROWN attack itself was reported to OpenSSL, as explained in this OpenSSL blogpost:
https://www.openssl.org/blog/blog/2016/03/01/an-openssl-users-guide-to-drown/
Thanks!
Severity: Low
A malicious client can negotiate SSLv2 ciphers that have been disabled on the server and complete SSLv2 handshakes even if all SSLv2 ciphers have been disabled, provided that the SSLv2 pr
Bugzilla
CVE-2015-3197 openssl101e: OpenSSL: SSLv2 doesn't block disabled ciphers [epel-5]
bugzilla·2016-01-28·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197 openssl101e: OpenSSL: SSLv2 doesn't block disabled ciphers [epel-5]
CVE-2015-3197 openssl101e: OpenSSL: SSLv2 doesn't block disabled ciphers [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for openssl101e: see blocks
Bugzilla
CVE-2015-3197 mingw-openssl: OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
bugzilla·2016-01-28·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197 mingw-openssl: OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
CVE-2015-3197 mingw-openssl: OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
bugzilla·2016-01-28·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers
bugzilla·2016-01-26·CVSS 5.9
CVE-2015-3197 [MEDIUM] CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers
CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers
As per OpenSSL upstream:
A malicious client can negotiate SSLv2 ciphers that have been disabled on the server and complete SSLv2 handshakes even if all SSLv2 ciphers have been disabled, provided that the SSLv2 protocol was not also disabled via SSL_OP_NO_SSLv2.
This issue affects OpenSSL versions 1.0.2, 1.0.1.
OpenSSL 1.0.2 users should upgrade to 1.0.2f
OpenSSL 1.0.1 users should upgrade to 1.0.1r
This issue was reported to OpenSSL on 26th December 2015 by Nimrod Aviram and Sebastian Schinzel. The fix was developed by Nimrod Aviram with further development by Viktor Dukhovni of the OpenSSL development team.
Acknowledgements:
Name: the OpenSSL project
Upstream: Nimrod Aviram, Sebastian Schinzel
Discussion:
Statement:
Thi
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176373.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.htmlhttp://www.openssl.org/news/secadv/20160128.txthttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/82237http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034849https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=d81a1600588b726c2bdccda7efad3cc7a87d6245https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390893https://security.FreeBSD.org/advisories/FreeBSD-SA-16:11.openssl.aschttps://security.gentoo.org/glsa/201601-05https://www.kb.cert.org/vuls/id/257823http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176373.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.htmlhttp://www.openssl.org/news/secadv/20160128.txthttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/82237http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034849https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=d81a1600588b726c2bdccda7efad3cc7a87d6245https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390893https://security.FreeBSD.org/advisories/FreeBSD-SA-16:11.openssl.aschttps://security.gentoo.org/glsa/201601-05https://www.kb.cert.org/vuls/id/257823
2016-02-15
Published