CVE-2011-3389

SSL - Info Disclosure

Title source: llm
STIX 2.1

Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

Exploits (1)

nomisec WORKING POC 80 stars
by mpgn · poc
https://github.com/mpgn/BEAST-PoC

References (89)

Core 89
Core References
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/74829
Third Party Advisory x_refsource_misc
http://eprint.iacr.org/2004/111
Third Party Advisory x_refsource_misc
http://isc.sans.edu/diary/SSL+TLS+part+3+/11635
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48692
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254866602253&w=2
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133365109612558&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55322
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT5130
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=737506
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=132750579901589&w=2
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025997
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA12-010A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49388
Broken Link x_refsource_misc
http://ekoparty.org/2011/juliano-rizzo.php
Third Party Advisory x_refsource_confirm
http://downloads.asterisk.org/pub/security/AST-2016-001.html
Broken Link vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55351
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/864643
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49778
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2398
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48948
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
Patch, Vendor Advisory x_refsource_confirm
http://technet.microsoft.com/security/advisory/2588513
Broken Link vendor-advisory x_refsource_suse
https://hermes.opensuse.org/messages/13155432
Third Party Advisory, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-1384.html
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/windows/1151/
Broken Link vendor-advisory x_refsource_suse
https://hermes.opensuse.org/messages/13154861
Third Party Advisory x_refsource_misc
http://eprint.iacr.org/2006/136
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48915
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201203-02.xml
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=132872385320240&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48256
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026103
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT4999
Third Party Advisory x_refsource_confirm
http://www.imperialviolet.org/2011/09/23/chromeandbeast.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT5501
Broken Link, Patch x_refsource_misc
http://www.insecure.cl/Beast-SSL.rar
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT5001
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/mac/1160/
Third Party Advisory x_refsource_confirm
http://curl.haxx.se/docs/adv_20120124B.html
Third Party Advisory, Vendor Advisory x_refsource_confirm
http://www.opera.com/support/kb/view/1004/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026704
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0508.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45791
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029190
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2012:058
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47998
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254957702612&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49198
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2012-0006.html
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/windows/1160/
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=133728004526190&w=2
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unix/1151/
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/mac/1151/
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006
Third Party Advisory x_refsource_confirm
http://www.opera.com/docs/changelogs/unix/1160/
Not Applicable, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html
Broken Link x_refsource_confirm
http://support.apple.com/kb/HT5281
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=719047
Third Party Advisory x_refsource_misc
http://vnhacker.blogspot.com/2011/09/beast.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1263-1
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55350
Third Party Advisory x_refsource_confirm
http://www.ibm.com/developerworks/java/jdk/alerts/
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf

Scores

EPSS 0.0393
EPSS Percentile 88.4%

Details

CWE
CWE-326
Status published
Products (22)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
canonical/ubuntu_linux 11.04
canonical/ubuntu_linux 11.10
debian/debian_linux 5.0
debian/debian_linux 6.0
google/chrome
haxx/curl 7.10.6 - 7.23.1
microsoft/internet_explorer
microsoft/windows
... and 12 more
Published Sep 06, 2011
Tracked Since Feb 18, 2026