中危 OpenSSL 至 1.0.0i SSLv3 Downgrade POODLE 加密问题漏洞

CVE编号

CVE-2014-3566

利用情况

POC 已公开

补丁情况

官方补丁

披露时间

2014-10-15
漏洞描述
SSL-SSL(Secure Sockets Layer 安全套接层),及其继任者传输层安全(Transport Layer Security,TLS)是为网络通信提供安全及数据完整性的一种安全协议。
SSL V3 Protocol存在信息泄露漏洞,攻击者可以利用此漏洞发起中间人攻击,获取用户cookie等敏感信息。
解决建议
目前没有详细的解决方案提供:
http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
参考链接
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc
http://advisories.mageia.org/MGASA-2014-0416.html
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.asc
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
http://askubuntu.com/questions/537196/how-do-i-patch-workaround-sslv3-poodle-...
http://blog.cryptographyengineering.com/2014/10/attack-of-week-poodle.html
http://blog.nodejs.org/2014/10/23/node-v0-10-33-stable/
http://blogs.technet.com/b/msrc/archive/2014/10/14/security-advisory-3009008-...
http://docs.ipswitch.com/MOVEit/DMZ82/ReleaseNotes/MOVEitReleaseNotes82.pdf
http://downloads.asterisk.org/pub/security/AST-2014-011.html
http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting...
http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142330.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141114.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141158.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169361.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169374.html
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00066.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00000.html
http://marc.info/?l=bugtraq&m=141450452204552&w=2
http://marc.info/?l=bugtraq&m=141450973807288&w=2
http://marc.info/?l=bugtraq&m=141477196830952&w=2
http://marc.info/?l=bugtraq&m=141576815022399&w=2
http://marc.info/?l=bugtraq&m=141577087123040&w=2
http://marc.info/?l=bugtraq&m=141577350823734&w=2
http://marc.info/?l=bugtraq&m=141620103726640&w=2
http://marc.info/?l=bugtraq&m=141628688425177&w=2
http://marc.info/?l=bugtraq&m=141694355519663&w=2
http://marc.info/?l=bugtraq&m=141697638231025&w=2
http://marc.info/?l=bugtraq&m=141697676231104&w=2
http://marc.info/?l=bugtraq&m=141703183219781&w=2
http://marc.info/?l=bugtraq&m=141715130023061&w=2
http://marc.info/?l=bugtraq&m=141775427104070&w=2
http://marc.info/?l=bugtraq&m=141813976718456&w=2
http://marc.info/?l=bugtraq&m=141814011518700&w=2
http://marc.info/?l=bugtraq&m=141879378918327&w=2
http://marc.info/?l=bugtraq&m=142103967620673&w=2
http://marc.info/?l=bugtraq&m=142118135300698&w=2
http://marc.info/?l=bugtraq&m=142296755107581&w=2
http://marc.info/?l=bugtraq&m=142350196615714&w=2
http://marc.info/?l=bugtraq&m=142350298616097&w=2
http://marc.info/?l=bugtraq&m=142350743917559&w=2
http://marc.info/?l=bugtraq&m=142354438527235&w=2
http://marc.info/?l=bugtraq&m=142357976805598&w=2
http://marc.info/?l=bugtraq&m=142495837901899&w=2
http://marc.info/?l=bugtraq&m=142496355704097&w=2
http://marc.info/?l=bugtraq&m=142546741516006&w=2
http://marc.info/?l=bugtraq&m=142607790919348&w=2
http://marc.info/?l=bugtraq&m=142624590206005&w=2
http://marc.info/?l=bugtraq&m=142624619906067
http://marc.info/?l=bugtraq&m=142624619906067&w=2
http://marc.info/?l=bugtraq&m=142624679706236&w=2
http://marc.info/?l=bugtraq&m=142624719706349&w=2
http://marc.info/?l=bugtraq&m=142660345230545&w=2
http://marc.info/?l=bugtraq&m=142721830231196&w=2
http://marc.info/?l=bugtraq&m=142721887231400&w=2
http://marc.info/?l=bugtraq&m=142740155824959&w=2
http://marc.info/?l=bugtraq&m=142791032306609&w=2
http://marc.info/?l=bugtraq&m=142804214608580&w=2
http://marc.info/?l=bugtraq&m=142805027510172&w=2
http://marc.info/?l=bugtraq&m=142962817202793&w=2
http://marc.info/?l=bugtraq&m=143039249603103&w=2
http://marc.info/?l=bugtraq&m=143101048219218&w=2
http://marc.info/?l=bugtraq&m=143290371927178&w=2
http://marc.info/?l=bugtraq&m=143290437727362&w=2
http://marc.info/?l=bugtraq&m=143290522027658&w=2
http://marc.info/?l=bugtraq&m=143290583027876&w=2
http://marc.info/?l=bugtraq&m=143558137709884&w=2
http://marc.info/?l=bugtraq&m=143558192010071&w=2
http://marc.info/?l=bugtraq&m=143628269912142&w=2
http://marc.info/?l=bugtraq&m=144101915224472&w=2
http://marc.info/?l=bugtraq&m=144251162130364&w=2
http://marc.info/?l=bugtraq&m=144294141001552&w=2
http://marc.info/?l=bugtraq&m=145983526810210&w=2
http://marc.info/?l=openssl-dev&m=141333049205629&w=2
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3566.html
http://rhn.redhat.com/errata/RHSA-2014-1652.html
http://rhn.redhat.com/errata/RHSA-2014-1653.html
http://rhn.redhat.com/errata/RHSA-2014-1692.html
http://rhn.redhat.com/errata/RHSA-2014-1876.html
http://rhn.redhat.com/errata/RHSA-2014-1877.html
http://rhn.redhat.com/errata/RHSA-2014-1880.html
http://rhn.redhat.com/errata/RHSA-2014-1881.html
http://rhn.redhat.com/errata/RHSA-2014-1882.html
http://rhn.redhat.com/errata/RHSA-2014-1920.html
http://rhn.redhat.com/errata/RHSA-2014-1948.html
http://rhn.redhat.com/errata/RHSA-2015-0068.html
http://rhn.redhat.com/errata/RHSA-2015-0079.html
http://rhn.redhat.com/errata/RHSA-2015-0080.html
http://rhn.redhat.com/errata/RHSA-2015-0085.html
http://rhn.redhat.com/errata/RHSA-2015-0086.html
http://rhn.redhat.com/errata/RHSA-2015-0264.html
http://rhn.redhat.com/errata/RHSA-2015-0698.html
http://rhn.redhat.com/errata/RHSA-2015-1545.html
http://rhn.redhat.com/errata/RHSA-2015-1546.html
http://secunia.com/advisories/59627
http://secunia.com/advisories/60056
http://secunia.com/advisories/60206
http://secunia.com/advisories/60792
http://secunia.com/advisories/60859
http://secunia.com/advisories/61019
http://secunia.com/advisories/61130
http://secunia.com/advisories/61303
http://secunia.com/advisories/61316
http://secunia.com/advisories/61345
http://secunia.com/advisories/61359
http://secunia.com/advisories/61782
http://secunia.com/advisories/61810
http://secunia.com/advisories/61819
http://secunia.com/advisories/61825
http://secunia.com/advisories/61827
http://secunia.com/advisories/61926
http://secunia.com/advisories/61995
http://support.apple.com/HT204244
http://support.citrix.com/article/CTX200238
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa...
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021431
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021439
http://www-01.ibm.com/support/docview.wss?uid=swg21686997
http://www-01.ibm.com/support/docview.wss?uid=swg21687172
http://www-01.ibm.com/support/docview.wss?uid=swg21687611
http://www-01.ibm.com/support/docview.wss?uid=swg21688283
http://www-01.ibm.com/support/docview.wss?uid=swg21692299
http://www.debian.org/security/2014/dsa-3053
http://www.debian.org/security/2015/dsa-3144
http://www.debian.org/security/2015/dsa-3147
http://www.debian.org/security/2015/dsa-3253
http://www.debian.org/security/2016/dsa-3489
http://www.kb.cert.org/vuls/id/577193
http://www.mandriva.com/security/advisories?name=MDVSA-2014:203
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/archive/1/533724/100/0/threaded
http://www.securityfocus.com/archive/1/533746
http://www.securityfocus.com/archive/1/533747
http://www.securityfocus.com/bid/70574
http://www.securitytracker.com/id/1031029
http://www.securitytracker.com/id/1031039
http://www.securitytracker.com/id/1031085
http://www.securitytracker.com/id/1031086
http://www.securitytracker.com/id/1031087
http://www.securitytracker.com/id/1031088
http://www.securitytracker.com/id/1031089
http://www.securitytracker.com/id/1031090
http://www.securitytracker.com/id/1031091
http://www.securitytracker.com/id/1031092
http://www.securitytracker.com/id/1031093
http://www.securitytracker.com/id/1031094
http://www.securitytracker.com/id/1031095
http://www.securitytracker.com/id/1031096
http://www.securitytracker.com/id/1031105
http://www.securitytracker.com/id/1031106
http://www.securitytracker.com/id/1031107
http://www.securitytracker.com/id/1031120
http://www.securitytracker.com/id/1031123
http://www.securitytracker.com/id/1031124
http://www.securitytracker.com/id/1031130
http://www.securitytracker.com/id/1031131
http://www.securitytracker.com/id/1031132
http://www.ubuntu.com/usn/USN-2486-1
http://www.ubuntu.com/usn/USN-2487-1
http://www.us-cert.gov/ncas/alerts/TA14-290A
http://www.vmware.com/security/advisories/VMSA-2015-0003.html
http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in...
http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisori...
https://access.redhat.com/articles/1232123
https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of...
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_openssl6
https://bto.bluecoat.com/security-advisory/sa83
https://bugzilla.mozilla.org/show_bug.cgi?id=1076983
https://bugzilla.redhat.com/show_bug.cgi?id=1152789
https://devcentral.f5.com/articles/cve-2014-3566-removing-sslv3-from-big-ip
https://github.com/mpgn/poodle-PoC
https://groups.google.com/forum/#%21topic/docker-user/oYm0i3xShJU
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n...
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n...
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n...
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n...
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
https://kc.mcafee.com/corporate/index?page=content&id=SB10090
https://kc.mcafee.com/corporate/index?page=content&id=SB10091
https://kc.mcafee.com/corporate/index?page=content&id=SB10104
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637d...
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84...
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d...
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9...
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1a...
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e57...
https://puppet.com/security/cve/poodle-sslv3-vulnerability
https://security.gentoo.org/glsa/201507-14
https://security.gentoo.org/glsa/201606-11
https://security.netapp.com/advisory/ntap-20141015-0001/
https://support.apple.com/HT205217
https://support.apple.com/kb/HT6527
https://support.apple.com/kb/HT6529
https://support.apple.com/kb/HT6531
https://support.apple.com/kb/HT6535
https://support.apple.com/kb/HT6536
https://support.apple.com/kb/HT6541
https://support.apple.com/kb/HT6542
https://support.citrix.com/article/CTX216642
https://support.lenovo.com/product_security/poodle
https://support.lenovo.com/us/en/product_security/poodle
https://technet.microsoft.com/library/security/3009008.aspx
https://www-01.ibm.com/support/docview.wss?uid=swg21688165
https://www.arista.com/en/support/advisories-notices/security-advisories/1015...
https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_to...
https://www.dfranke.us/posts/2014-10-14-how-poodle-happened.html
https://www.elastic.co/blog/logstash-1-4-3-released
https://www.imperialviolet.org/2014/10/14/poodle.html
https://www.openssl.org/news/secadv_20141015.txt
https://www.openssl.org/~bodo/ssl-poodle.pdf
https://www.suse.com/support/kb/doc.php?id=7015773
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 openssl openssl 0.9.8 -
运行在以下环境
应用 openssl openssl 0.9.8a -
运行在以下环境
应用 openssl openssl 0.9.8b -
运行在以下环境
应用 openssl openssl 0.9.8c -
运行在以下环境
应用 openssl openssl 0.9.8d -
运行在以下环境
应用 openssl openssl 0.9.8e -
运行在以下环境
应用 openssl openssl 0.9.8f -
运行在以下环境
应用 openssl openssl 0.9.8g -
运行在以下环境
应用 openssl openssl 0.9.8h -
运行在以下环境
应用 openssl openssl 0.9.8i -
运行在以下环境
应用 openssl openssl 0.9.8j -
运行在以下环境
应用 openssl openssl 0.9.8k -
运行在以下环境
应用 openssl openssl 0.9.8l -
运行在以下环境
应用 openssl openssl 0.9.8m -
运行在以下环境
应用 openssl openssl 0.9.8n -
运行在以下环境
应用 openssl openssl 0.9.8o -
运行在以下环境
应用 openssl openssl 0.9.8p -
运行在以下环境
应用 openssl openssl 0.9.8q -
运行在以下环境
应用 openssl openssl 0.9.8r -
运行在以下环境
应用 openssl openssl 0.9.8s -
运行在以下环境
应用 openssl openssl 0.9.8t -
运行在以下环境
应用 openssl openssl 0.9.8u -
运行在以下环境
应用 openssl openssl 0.9.8v -
运行在以下环境
应用 openssl openssl 0.9.8w -
运行在以下环境
应用 openssl openssl 0.9.8x -
运行在以下环境
应用 openssl openssl 0.9.8y -
运行在以下环境
应用 openssl openssl 0.9.8z -
运行在以下环境
应用 openssl openssl 0.9.8za -
运行在以下环境
应用 openssl openssl 0.9.8zb -
运行在以下环境
应用 openssl openssl 1.0.0 -
运行在以下环境
应用 openssl openssl 1.0.0a -
运行在以下环境
应用 openssl openssl 1.0.0b -
运行在以下环境
应用 openssl openssl 1.0.0c -
运行在以下环境
应用 openssl openssl 1.0.0d -
运行在以下环境
应用 openssl openssl 1.0.0e -
运行在以下环境
应用 openssl openssl 1.0.0f -
运行在以下环境
应用 openssl openssl 1.0.0g -
运行在以下环境
应用 openssl openssl 1.0.0h -
运行在以下环境
应用 openssl openssl 1.0.0i -
运行在以下环境
应用 openssl openssl 1.0.0j -
运行在以下环境
应用 openssl openssl 1.0.0k -
运行在以下环境
应用 openssl openssl 1.0.0l -
运行在以下环境
应用 openssl openssl 1.0.0m -
运行在以下环境
应用 openssl openssl 1.0.0n -
运行在以下环境
应用 openssl openssl 1.0.1 -
运行在以下环境
应用 openssl openssl 1.0.1a -
运行在以下环境
应用 openssl openssl 1.0.1b -
运行在以下环境
应用 openssl openssl 1.0.1c -
运行在以下环境
应用 openssl openssl 1.0.1d -
运行在以下环境
应用 openssl openssl 1.0.1e -
运行在以下环境
应用 openssl openssl 1.0.1f -
运行在以下环境
应用 openssl openssl 1.0.1g -
运行在以下环境
应用 openssl openssl 1.0.1h -
运行在以下环境
应用 openssl openssl 1.0.1i -
运行在以下环境
应用 oracle database 11.2.0.4 -
运行在以下环境
应用 oracle database 12.1.0.2 -
运行在以下环境
系统 apple mac_os_x * Up to
(including)
10.10.1
运行在以下环境
系统 debian debian_linux 7.0 -
运行在以下环境
系统 debian debian_linux 8.0 -
运行在以下环境
系统 fedoraproject fedora 19 -
运行在以下环境
系统 fedoraproject fedora 20 -
运行在以下环境
系统 fedoraproject fedora 21 -
运行在以下环境
系统 ibm aix 5.3 -
运行在以下环境
系统 ibm aix 6.1 -
运行在以下环境
系统 ibm aix 7.1 -
运行在以下环境
系统 ibm vios 2.2.0.10 -
运行在以下环境
系统 ibm vios 2.2.0.11 -
运行在以下环境
系统 ibm vios 2.2.0.12 -
运行在以下环境
系统 ibm vios 2.2.0.13 -
运行在以下环境
系统 ibm vios 2.2.1.0 -
运行在以下环境
系统 ibm vios 2.2.1.1 -
运行在以下环境
系统 ibm vios 2.2.1.3 -
运行在以下环境
系统 ibm vios 2.2.1.4 -
运行在以下环境
系统 ibm vios 2.2.1.5 -
运行在以下环境
系统 ibm vios 2.2.1.6 -
运行在以下环境
系统 ibm vios 2.2.1.7 -
运行在以下环境
系统 ibm vios 2.2.1.8 -
运行在以下环境
系统 ibm vios 2.2.1.9 -
运行在以下环境
系统 ibm vios 2.2.2.0 -
运行在以下环境
系统 ibm vios 2.2.2.1 -
运行在以下环境
系统 ibm vios 2.2.2.2 -
运行在以下环境
系统 ibm vios 2.2.2.3 -
运行在以下环境
系统 ibm vios 2.2.2.4 -
运行在以下环境
系统 ibm vios 2.2.2.5 -
运行在以下环境
系统 ibm vios 2.2.3.0 -
运行在以下环境
系统 ibm vios 2.2.3.1 -
运行在以下环境
系统 ibm vios 2.2.3.2 -
运行在以下环境
系统 ibm vios 2.2.3.3 -
运行在以下环境
系统 ibm vios 2.2.3.4 -
运行在以下环境
系统 mageia mageia 3.0 -
运行在以下环境
系统 mageia mageia 4.0 -
运行在以下环境
系统 netbsd netbsd 5.1 -
运行在以下环境
系统 netbsd netbsd 5.1.1 -
运行在以下环境
系统 netbsd netbsd 5.1.2 -
运行在以下环境
系统 netbsd netbsd 5.1.3 -
运行在以下环境
系统 netbsd netbsd 5.1.4 -
运行在以下环境
系统 netbsd netbsd 5.2 -
运行在以下环境
系统 netbsd netbsd 5.2.1 -
运行在以下环境
系统 netbsd netbsd 5.2.2 -
运行在以下环境
系统 netbsd netbsd 6.0 -
运行在以下环境
系统 netbsd netbsd 6.0.1 -
运行在以下环境
系统 netbsd netbsd 6.0.2 -
运行在以下环境
系统 netbsd netbsd 6.0.3 -
运行在以下环境
系统 netbsd netbsd 6.0.4 -
运行在以下环境
系统 netbsd netbsd 6.0.5 -
运行在以下环境
系统 netbsd netbsd 6.0.6 -
运行在以下环境
系统 netbsd netbsd 6.1 -
运行在以下环境
系统 netbsd netbsd 6.1.1 -
运行在以下环境
系统 netbsd netbsd 6.1.2 -
运行在以下环境
系统 netbsd netbsd 6.1.3 -
运行在以下环境
系统 netbsd netbsd 6.1.4 -
运行在以下环境
系统 netbsd netbsd 6.1.5 -
运行在以下环境
系统 novell suse_linux_enterprise_desktop 10.0 -
运行在以下环境
系统 novell suse_linux_enterprise_desktop 11.0 -
运行在以下环境
系统 novell suse_linux_enterprise_desktop 12.0 -
运行在以下环境
系统 novell suse_linux_enterprise_desktop 9.0 -
运行在以下环境
系统 novell suse_linux_enterprise_server 11.0 -
运行在以下环境
系统 novell suse_linux_enterprise_server 12.0 -
运行在以下环境
系统 novell suse_linux_enterprise_software_development_kit 11.0 -
运行在以下环境
系统 novell suse_linux_enterprise_software_development_kit 12.0 -
运行在以下环境
系统 opensuse opensuse 12.3 -
运行在以下环境
系统 opensuse opensuse 13.1 -
运行在以下环境
系统 redhat enterprise_linux 5 -
运行在以下环境
系统 redhat enterprise_linux_desktop 6.0 -
运行在以下环境
系统 redhat enterprise_linux_desktop 7.0 -
运行在以下环境
系统 redhat enterprise_linux_desktop_supplementary 5.0 -
运行在以下环境
系统 redhat enterprise_linux_desktop_supplementary 6.0 -
运行在以下环境
系统 redhat enterprise_linux_server 6.0 -
运行在以下环境
系统 redhat enterprise_linux_server 7.0 -
运行在以下环境
系统 redhat enterprise_linux_server_supplementary 5.0 -
运行在以下环境
系统 redhat enterprise_linux_server_supplementary 6.0 -
运行在以下环境
系统 redhat enterprise_linux_server_supplementary 7.0 -
运行在以下环境
系统 redhat enterprise_linux_workstation 6.0 -
运行在以下环境
系统 redhat enterprise_linux_workstation 7.0 -
运行在以下环境
系统 redhat enterprise_linux_workstation_supplementary 6.0 -
运行在以下环境
系统 redhat enterprise_linux_workstation_supplementary 7.0 -
运行在以下环境
系统 redhat_5 java-1.7.0-openjdk * Up to
(excluding)
1:1.7.0.75-2.5.4.0.el5_11
运行在以下环境
系统 redhat_6 java-1.6.0-ibm * Up to
(excluding)
1:1.6.0.16.2-1jpp.1.el5
运行在以下环境
系统 redhat_7 nss * Up to
(excluding)
0:3.16.2.3-1.el5_11
运行在以下环境
系统 suse_12 apache2-mod_nss * Up to
(excluding)
1.0.14-10.14
运行在以下环境
系统 ubuntu_12.04.5_lts nss * Up to
(excluding)
3.17.1-0ubuntu0.12.04.1
运行在以下环境
系统 ubuntu_14.04.6_lts nss * Up to
(excluding)
2:3.17.1-0ubuntu0.14.04.1
运行在以下环境
系统 ubuntu_16.04.7_lts nss * Up to
(excluding)
2:3.17.1-0ubuntu1
运行在以下环境
系统 ubuntu_18.04.5_lts nss * Up to
(excluding)
2:3.17.1-0ubuntu1
运行在以下环境
系统 ubuntu_18.10 nss * Up to
(excluding)
2:3.17.1-0ubuntu1
阿里云评分
4.1
  • 攻击路径
    远程
  • 攻击复杂度
    困难
  • 权限要求
    无需权限
  • 影响范围
    越权影响
  • EXP成熟度
    POC 已公开
  • 补丁情况
    官方补丁
  • 数据保密性
    无影响
  • 数据完整性
    无影响
  • 服务器危害
    无影响
  • 全网数量
    100
CWE-ID 漏洞类型
阿里云安全产品覆盖情况