CVE-2016-0703

MEDIUM

OpenSSL < 0.9.8zf, 1.0.0 < 1.0.0r, 1.0.1 < 1.0.1m, 1.0.2 < 1.0.2a - SSLv2 CLIENT-MASTER-KEY Info Exposure

Title source: llm
STIX 2.1

Description

The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.

References (31)

Core 31
Core References
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/83743
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/201603-15
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1035133
Various Sources
https://drownattack.com

Scores

CVSS v3 5.9
EPSS 0.0486
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (33)
openssl/openssl 1.0.0 (6 CPE variants)
openssl/openssl 1.0.0a
openssl/openssl 1.0.0b
openssl/openssl 1.0.0c
openssl/openssl 1.0.0d
openssl/openssl 1.0.0e
openssl/openssl 1.0.0f
openssl/openssl 1.0.0g
openssl/openssl 1.0.0h
openssl/openssl 1.0.0i
... and 23 more
Published Mar 02, 2016
Tracked Since Feb 18, 2026