CVE-2015-4000
published 2015-05-21CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which…
PriorityP351low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EXPLOIT
EPSS
99.86%
100.0th percentile
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 8.3 | — |
| apple | mac_os_x | <= 10.10.3 | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nss | < nss 2:3.19.1-1 (bookworm) | nss 2:3.19.1-1 (bookworm) |
| debian | openjdk-8 | < nss 2:3.19.1-1 (bookworm) | nss 2:3.19.1-1 (bookworm) |
| debian | openssl | < nss 2:3.19.1-1 (bookworm) | nss 2:3.19.1-1 (bookworm) |
| geddyjs | geddy | >= 0 < 13.0.8 | 13.0.8 |
| hp | hp-ux | — | — |
| ibm | content_manager | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 39.0+build5-0ubuntu0.14.04.1 | 39.0+build5-0ubuntu0.14.04.1 |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_os | — | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect TLS ClientHello packets where DHE_EXPORT ciphersuites are being negotiated — a server supporting DHE_EXPORT ciphers is exploitable as a downgrade target ↗
- →Flag TLS handshakes where DH parameters are 512 bits (export-grade); the MITM rewrites ClientHello replacing DHE with DHE_EXPORT and ServerHello replacing DHE_EXPORT with DHE ↗
- →Monitor for use of pre-computed weak DH primes associated with Apache 2.1.5–2.4.7 and OpenSSL default parameters, which enable 'compute once, use many' offline decryption ↗
- →Inspect TLS handshakes for the DHE_EXPORT downgrade + TLS False Start combination: server supports DHE_EXPORT or 512-bit DHE params AND client uses TLS False Start extension ↗
- →Detect abnormally long TLS handshake durations (several minutes) which may indicate an active MITM computing the 512-bit DH connection key in real time during the handshake ↗
- →Check server TLS configuration for presence of DHE_EXPORT cipher suites in the enabled cipher list; application-specific config may re-enable export ciphers even when the library default excludes them ↗
- ·NSS versions shipped with RHEL 4, 5, 6, and 7 accepted 512-bit DHE parameters prior to the fix; the fix raises the minimum to 1023 bits (nss-3.19.1) ↗
- ·OpenSSL packages in RHEL 6 and 7 do not include DHE_EXPORT in the DEFAULT cipher list, but application-level configuration can override this and re-enable export ciphers ↗
- ·Java JDK implementations (OpenJDK, Oracle JDK, IBM JDK) previously accepted 512-bit (or even 256-bit for IBM) DH parameters; the jdk.tls.disabledAlgorithms security property controls the minimum key size ↗
- ·openssl097a (RHEL 5), openssl098e (RHEL 6/7), and openssl for JBoss EWS 1 are marked 'Will not fix', meaning these remain permanently vulnerable in those configurations ↗
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian3.7LOW
vendor_oracle3.7LOW
vendor_redhat3.7LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle SPARC Enterprise Server XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)
vuldb·2026-05-28·CVSS 3.7
CVE-2015-4000 [LOW] Oracle SPARC Enterprise Server XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)
A vulnerability was found in Oracle SPARC Enterprise Server and classified as problematic. This impacts an unknown function of the component XCP Firmware. The manipulation results in cryptographic issues.
This vulnerability is cataloged as CVE-2015-4000. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Enterprise Manager Ops Center 12.4.0.0 User Interface cryptographic issue (Nessus ID 84405 / ID 124568)
vuldb·2026-05-28·CVSS 3.7
CVE-2015-4000 [LOW] Oracle Enterprise Manager Ops Center 12.4.0.0 User Interface cryptographic issue (Nessus ID 84405 / ID 124568)
A vulnerability described as problematic has been identified in Oracle Enterprise Manager Ops Center 12.4.0.0. Affected is an unknown function of the component User Interface. The manipulation results in cryptographic issues.
This vulnerability is reported as CVE-2015-4000. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
VulDB
Oracle Fujitsu M10-1/M10-4/M10-4S Servers up to XCP 2270 XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)
vuldb·2026-05-28·CVSS 3.7
CVE-2015-4000 [LOW] Oracle Fujitsu M10-1/M10-4/M10-4S Servers up to XCP 2270 XCP Firmware cryptographic issue (Nessus ID 85301 / ID 350152)
A vulnerability, which was classified as critical, has been found in Oracle Fujitsu M10-1, M10-4 and M10-4S Servers up to XCP 2270. The affected element is an unknown function of the component XCP Firmware. This manipulation causes cryptographic issues.
This vulnerability is tracked as CVE-2015-4000. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle Secure Global Desktop 4.63/4.71/5.2 OpenSSL cryptographic issue (Nessus ID 87764 / ID 350152)
vuldb·2026-05-28·CVSS 3.7
CVE-2015-4000 [LOW] Oracle Secure Global Desktop 4.63/4.71/5.2 OpenSSL cryptographic issue (Nessus ID 87764 / ID 350152)
A vulnerability labeled as problematic has been found in Oracle Secure Global Desktop 4.63/4.71/5.2. Impacted is an unknown function of the component OpenSSL. The manipulation results in cryptographic issues.
This vulnerability is known as CVE-2015-4000. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.
VulDB
TLS Protocol up to 1.2 DHE_EXPORT Ciphersuite Logjam cryptographic issue (Nessus ID 83937 / ID 350152)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-4000 [LOW] TLS Protocol up to 1.2 DHE_EXPORT Ciphersuite Logjam cryptographic issue (Nessus ID 83937 / ID 350152)
A vulnerability was found in TLS Protocol up to 1.2. It has been rated as very critical. This affects an unknown part of the component DHE_EXPORT Ciphersuite. Performing a manipulation results in cryptographic issues (Logjam).
This vulnerability is known as CVE-2015-4000. Remote exploitation of the attack is possible. No exploit is available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to change the configuration settings.
VulDB
Oracle Communications Messaging Server 7.0.5/8.0 cryptographic issue (Nessus ID 90150 / ID 350152)
vuldb·2026-05-27·CVSS 3.7
CVE-2015-4000 [LOW] Oracle Communications Messaging Server 7.0.5/8.0 cryptographic issue (Nessus ID 90150 / ID 350152)
A vulnerability, which was classified as critical, was found in Oracle Communications Messaging Server 7.0.5/8.0. This impacts an unknown function. Such manipulation leads to cryptographic issues.
This vulnerability is documented as CVE-2015-4000. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-v98w-p8f7-9qqf: The TLS protocol 1
ghsa_unreviewed·2022-05-13
CVE-2015-4000 [MEDIUM] GHSA-v98w-p8f7-9qqf: The TLS protocol 1
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
GHSA
Directory Traversal in geddy
ghsa·2017-10-24
CVE-2015-5688 [HIGH] CWE-22 Directory Traversal in geddy
Directory Traversal in geddy
Versions 13.0.8 and earlier of geddy are vulnerable to a directory traversal attack via URI encoded attack vectors.
### Proof of Concept
```
http://localhost:4000/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd
```
## Recommendation
Update geddy to version >= 13.0.8
OSV
openjdk-7 vulnerabilities
osv·2015-07-30·CVSS 9.8
CVE-2015-2590 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this update modifies OpenJDK behavior to
reject
OSV
thunderbird vulnerabilities
osv·2015-07-20·CVSS 4.3
CVE-2015-2721 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Bob Clary, Christian Holler, Bobby Holley, and Andrew McCreight discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted website in a browsing context, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-2724)
Ronald Crane discovered multiple security vulnerabilities. If a
OSV
firefox vulnerabilities
osv·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015-2733)
Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence
Cole, Steve Fink, Mats Palmgren, W
OSV
CVE-2015-4000: The TLS protocol 1
osv·2015-05-21·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000: The TLS protocol 1
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: User Interface (OpenSSL) — CVE-2015-4000
vendor_oracle·2021-01-15·CVSS 3.7
CVE-2015-4000 [LOW] Oracle Oracle Enterprise Manager Risk Matrix: User Interface (OpenSSL) — CVE-2015-4000
Oracle Oracle Enterprise Manager Risk Matrix: User Interface (OpenSSL) vulnerability
CVE: CVE-2015-4000
CVSS: 3.7
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Palo Alto
PAN-SA-2016-0028 OpenSSL Vulnerabilities
vendor_paloalto·2016-10-18·CVSS 7.5
CVE-2015-4000 [HIGH] CWE-119 PAN-SA-2016-0028 OpenSSL Vulnerabilities
PAN-SA-2016-0028 OpenSSL Vulnerabilities
The OpenSSL library has been found to contain several vulnerabilities CVE-2015-4000, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, CVE-2015-1791, CVE-2014-8176. Palo Alto Networks software makes use of the vulnerable library. (Ref # PAN-48954/81411) The OpenSSL library in use by PAN-OS is patched on a regular basis. Severities of the CVEs listed under the summary section range from low to moderate but have not been shown to be exploitable at the time of this advisory. This issue affects PAN-OS 5.0.19 and earlier; PAN-OS 5.1.12 and earlier; PAN-OS 6.0.13 and earlier; PAN-OS 6.1.12 and earlier; PAN-OS 7.0.7 and earlier CVE CVSS Summary CVE-2014-8176 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P The dtls1_clear_queues function in ssl/d1_lib.c in OpenSS
Palo Alto
PAN-SA-2016-0020 OpenSSL Vulnerabilities
vendor_paloalto·2016-08-15·CVSS 7.5
CVE-2014-8176 [HIGH] CWE-119 PAN-SA-2016-0020 OpenSSL Vulnerabilities
PAN-SA-2016-0020 OpenSSL Vulnerabilities
The OpenSSL library has been found to contain several vulnerabilities CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-1794, CVE-2015-3195, CVE-2015-4000, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2842. Palo Alto Networks software makes use of the vulnerable library. (Ref # 95622). The OpenSSL library in use by PAN-OS is patched on a regular basis. Severities of the CVEs listed under the summary section range from low to high but, have not been shown to be exploitable at the time of this advisory. This issue affects PAN-OS 5.0.X; PAN-OS-5.1.X; PAN-OS 6.0.13 and earlier; PAN-OS 6.1.12 and earlier; PAN-OS 7.0.8 and earlier; PAN-OS 7.1.3 and earl
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 9.8
CVE-2015-2590 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2808 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2613 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-07-20·CVSS 4.3
CVE-2015-2721 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Bob Clary, Christian Holler, Bobby Holley, and Andrew McCreight discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted website in a browsing context, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-27
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-15·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and
later releases.
This update provides the corresponding update for Ubuntu 12.04 LTS.
Original advisory details:
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015
BSD
FreeBSD-SA-15:10.openssl: Multiple OpenSSL vulnerabilities
bsd_advisories·2015-06-12·CVSS 4.3
CVE-2014-8176 [MEDIUM] FreeBSD-SA-15:10.openssl: Multiple OpenSSL vulnerabilities
FreeBSD-SA-15:10.openssl Security Advisory
The FreeBSD Project
Topic: Multiple OpenSSL vulnerabilities
Category: contrib
Module: openssl
Announced: 2015-06-12
Affects: All supported versions of FreeBSD.
Corrected: 2015-06-11 19:07:45 UTC (stable/10, 10.1-STABLE)
2015-06-12 07:23:55 UTC (releng/10.1, 10.1-RELEASE-p12)
2015-06-11 19:39:27 UTC (stable/9, 9.3-STABLE)
2015-06-12 07:23:55 UTC (releng/9.3, 9.3-RELEASE-p16)
2015-06-11 19:39:27 UTC (stable/8, 8.4-STABLE)
2015-06-12 07:23:55 UTC (releng/8.4, 8.4-RELEASE-p30)
CVE Name: CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791
CVE-2015-1792, CVE-2015-4000
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Backg
Red Hat
LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
vendor_redhat·2015-05-20·CVSS 3.7
CVE-2015-4000 [LOW] CWE-327 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
A flaw was found in the way the TLS protocol composes the Diffie-Hellman exchange (for both export and non-export grade cipher suites). An attacker could use this flaw to downgrade a DHE connection to use export-grade key sizes, which could then be broken by sufficient pre-computation. This can lead to a passive man-i
Debian
CVE-2015-4000: nss - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a ...
vendor_debian·2015·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000: nss - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a ...
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Scope: local
bookworm: resolved (fixed in 2:3.19.1-1)
bullseye: resolved (fixed in 2:3.19.1-1)
forky: resolved (fixed in 2:3.19.1-1)
sid: resolved (fixed in 2:3.19.1-1)
trixie: resolved (fixed in 2:3.19.1-1)
Apple
CVE-2015-4000: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-4000
Component: CVE-ID
Apple
CVE-2015-4000: iOS 8.4
vendor_apple·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-4000
Component: CVE-ID
No detection rules found.
Exploit-DB
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
exploitdb·2015-08-31
CVE-2015-7243 Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
---
#Exploit Title: Boxoft wav to mp3 converter SEH bypass technique tested on Win7x64
# Date: 8-31-2015
# Software Link: http://www.boxoft.com/wav-to-mp3/
# Exploit Author: Robbie Corley
# Contact: [email protected]
# Website:
# Target: Windows 7 Enterprise x64
# CVE:
# Category: Local Exploit
#
# Description:
# A buffer overflow was found after constructing a .wav payload over 4000 characters and attempting to convert the payload to a .mp3 file
my $buff = "\x41" x 4132;
#my $nseh = "\x42" x 4;
#my $seh = "\x43" x 4;
my $endofbuff = "\x41" x 5860;
$nseh = "\xeb\x06\x90\x90"; # jump to shellcode
$seh = pack('V',0x0040144c); # pop pop retn
#MessageBox Shellc0de
#https://www.exploit-db.com/exploits/28996/
my $shellcode
Metasploit
SSL/TLS Version Detection
metasploit
SSL/TLS Version Detection
SSL/TLS Version Detection
Check if a server supports a given version of SSL/TLS and cipher suites. The certificate is stored in loot, and any known vulnerabilities against that SSL version and cipher suite combination are checked. These checks include POODLE, deprecated protocols, expired/not valid certs, low key strength, null cipher suites, certificates signed with MD5, DROWN, RC4 ciphers, exportable ciphers, LOGJAM, and BEAST.
Bugzilla
CVE-2015-4000 openssl: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
bugzilla·2015-05-23·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000 openssl: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
CVE-2015-4000 openssl: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2015-4000 nss: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
bugzilla·2015-05-23·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000 nss: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
CVE-2015-4000 nss: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
bugzilla·2015-05-20·CVSS 3.7
CVE-2015-4000 [LOW] CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
TLS connections using Diffie-Hellman key exchange protocol were found to be vulnerable to an attack, in which a man-in-the-middle attacker could downgrade vulnerable TLS connections to 512-bit export-grade cryptography. The attack affects any server that supports DHE_EXPORT ciphers. This attack can be conduted by precomputation on the 512 bit primes given in two popular sets of weak Diffie-Hellman parameters, namely Apache 2.1.5 - 2.4.7 and OpenSSL.
The following attack scenarios are possible:
1. Offline Decryption of Weak DHE Connections:
This attack requires that the server default to using a Diffie-Hellman key exchange with 512-bit parameters. In this attack, there is a pa
Bugzilla
NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
bugzilla·2015-03-02
[MEDIUM] NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
Discussion:
The following issue needs to be externally coordinated.
Matthew Green informed me this morning of a potential issue in libssl
and DHE processing. The scenario is a TLS server which is configured
for export DHE modes, such as:
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA
As well as stronger modes.
In this scenario, the server is supposed to use a 512-bit DHE key.
If the server uses a static key rather than a fresh key for each
connection, then it is potentially possible for an attacker to
break the key. At that point he modifies the client's ClientHello
to only offer the export DHE mode, causing the server to return
a valid ServerKeyExchange with that key. The attacker than computes
the master secret an
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
http://aix.software.ibm.com/aix/efixes/security/sendmail_advisory2.aschttp://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgeryhttp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.aschttp://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04876402http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04949778http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10681http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159314.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159351.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160117.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00094.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00097.htmlhttp://marc.info/?l=bugtraq&m=143506486712441&w=2http://marc.info/?l=bugtraq&m=143557934009303&w=2http://marc.info/?l=bugtraq&m=143558092609708&w=2http://marc.info/?l=bugtraq&m=143628304012255&w=2http://marc.info/?l=bugtraq&m=143637549705650&w=2http://marc.info/?l=bugtraq&m=143655800220052&w=2http://marc.info/?l=bugtraq&m=143880121627664&w=2http://marc.info/?l=bugtraq&m=144043644216842&w=2http://marc.info/?l=bugtraq&m=144050121701297&w=2http://marc.info/?l=bugtraq&m=144060576831314&w=2http://marc.info/?l=bugtraq&m=144060606031437&w=2http://marc.info/?l=bugtraq&m=144061542602287&w=2http://marc.info/?l=bugtraq&m=144069189622016&w=2http://marc.info/?l=bugtraq&m=144102017024820&w=2http://marc.info/?l=bugtraq&m=144104533800819&w=2http://marc.info/?l=bugtraq&m=144493176821532&w=2http://marc.info/?l=bugtraq&m=145409266329539&w=2http://openwall.com/lists/oss-security/2015/05/20/8http://rhn.redhat.com/errata/RHSA-2015-1072.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1185.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1197.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1624.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://support.citrix.com/article/CTX201114http://www-01.ibm.com/support/docview.wss?uid=swg21959111http://www-01.ibm.com/support/docview.wss?uid=swg21959195http://www-01.ibm.com/support/docview.wss?uid=swg21959325http://www-01.ibm.com/support/docview.wss?uid=swg21959453http://www-01.ibm.com/support/docview.wss?uid=swg21959481http://www-01.ibm.com/support/docview.wss?uid=swg21959517http://www-01.ibm.com/support/docview.wss?uid=swg21959530http://www-01.ibm.com/support/docview.wss?uid=swg21959539http://www-01.ibm.com/support/docview.wss?uid=swg21959636http://www-01.ibm.com/support/docview.wss?uid=swg21959812http://www-01.ibm.com/support/docview.wss?uid=swg21960191http://www-01.ibm.com/support/docview.wss?uid=swg21961717http://www-01.ibm.com/support/docview.wss?uid=swg21962455http://www-01.ibm.com/support/docview.wss?uid=swg21962739http://www-304.ibm.com/support/docview.wss?uid=swg21958984http://www-304.ibm.com/support/docview.wss?uid=swg21959132http://www-304.ibm.com/support/docview.wss?uid=swg21960041http://www-304.ibm.com/support/docview.wss?uid=swg21960194http://www-304.ibm.com/support/docview.wss?uid=swg21960380http://www-304.ibm.com/support/docview.wss?uid=swg21960418
+ 334 more references
2015-05-21
Published