4.3
CVSSv2

CVE-2008-7270

Published: 06/12/2010 Updated: 06/04/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

OpenSSL prior to 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote malicious users to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.4

openssl openssl 0.9.5

openssl openssl 0.9.6

openssl openssl 0.9.6e

openssl openssl 0.9.6d

openssl openssl 0.9.6j

openssl openssl 0.9.6m

openssl openssl 0.9.7a

openssl openssl 0.9.7

openssl openssl 0.9.7i

openssl openssl 0.9.7f

openssl openssl 0.9.7m

openssl openssl 0.9.7l

openssl openssl 0.9.5a

openssl openssl 0.9.6a

openssl openssl 0.9.6i

openssl openssl 0.9.6h

openssl openssl 0.9.2b

openssl openssl 0.9.1c

openssl openssl 0.9.7e

openssl openssl 0.9.7b

openssl openssl 0.9.8a

openssl openssl 0.9.8e

openssl openssl 0.9.8c

openssl openssl

openssl openssl 0.9.6g

openssl openssl 0.9.6f

openssl openssl 0.9.8g

openssl openssl 0.9.6l

openssl openssl 0.9.3

openssl openssl 0.9.7d

openssl openssl 0.9.7g

openssl openssl 0.9.8

openssl openssl 0.9.7k

openssl openssl 0.9.7j

openssl openssl 0.9.3a

openssl openssl 0.9.6c

openssl openssl 0.9.6b

openssl openssl 0.9.8f

openssl openssl 0.9.6k

openssl openssl 0.9.8h

openssl openssl 0.9.7c

openssl openssl 0.9.7h

openssl openssl 0.9.8b

openssl openssl 0.9.8d

Vendor Advisories

It was discovered that an old bug workaround in the SSL/TLS server code allowed an attacker to modify the stored session cache ciphersuite This could possibly allow an attacker to downgrade the ciphersuite to a weaker one on subsequent connections (CVE-2010-4180) ...