{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2015-4000", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the \"Logjam\" issue." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "url" : "http://openwall.com/lists/oss-security/2015/05/20/8" }, { "url" : "https://weakdh.org/" }, { "url" : "https://weakdh.org/imperfect-forward-secrecy.pdf" }, { "url" : "https://blog.cloudflare.com/logjam-the-latest-tls-vulnerability-explained/" }, { "url" : "https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/" }, { "url" : "https://www.suse.com/security/cve/CVE-2015-4000.html" }, { "url" : "https://www.openssl.org/news/secadv_20150611.txt" }, { "url" : "http://support.apple.com/kb/HT204941" }, { "url" : "http://support.apple.com/kb/HT204942" }, { "url" : "http://www.mozilla.org/security/announce/2015/mfsa2015-70.html" }, { "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=1138554" }, { "url" : "https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.1_release_notes" }, { "url" : "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21962455" }, { "url" : "http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html" }, { "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html" }, { "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html" }, { "url" : "http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/releaseNotes.htm" }, { "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html" }, { "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05128722" }, { "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763" }, { "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193083" }, { "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04740527" }, { "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04953655" }, { "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html" }, { "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html" }, { "url" : "http://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgery" }, { "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727" }, { "url" : "https://openssl.org/news/secadv/20150611.txt" }, { "url" : "http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04949778" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04918839" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923929" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21967893" }, { "url" : "http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04876402" }, { "url" : "https://bto.bluecoat.com/security-advisory/sa98" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21960041" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246" }, { "url" : "http://support.citrix.com/article/CTX201114" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959111" }, { "url" : "http://www.fortiguard.com/advisory/2015-05-20-logjam-attack" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119" }, { "url" : "http://aix.software.ibm.com/aix/efixes/security/sendmail_advisory2.asc" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21960191" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21962739" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21962816" }, { "url" : "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959195" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959325" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959453" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959481" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959517" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959530" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959539" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959636" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21959812" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21958984" }, { "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10122" }, { "url" : "https://www-304.ibm.com/support/docview.wss?uid=swg21959745" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21960380" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21960418" }, { "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21961717" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21959132" }, { "url" : "http://www-304.ibm.com/support/docview.wss?uid=swg21960194" }, { "url" : "https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098403" }, { "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10681" }, { "url" : "https://security.netapp.com/advisory/ntap-20150619-0001/" }, { "url" : "https://support.citrix.com/article/CTX216642" }, { "url" : "https://puppet.com/security/cve/CVE-2015-4000" }, { "url" : "http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.html" }, { "url" : "http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html" }, { "url" : "http://www.debian.org/security/2015/dsa-3324" }, { "url" : "http://www.debian.org/security/2015/dsa-3339" }, { "url" : "http://www.debian.org/security/2015/dsa-3300" }, { "url" : "http://www.debian.org/security/2015/dsa-3287" }, { "url" : "http://www.debian.org/security/2015/dsa-3316" }, { "url" : "http://www.debian.org/security/2016/dsa-3688" }, { "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159351.html" }, { "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159314.html" }, { "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160117.html" }, { "url" : "https://security.gentoo.org/glsa/201603-11" }, { "url" : "https://security.gentoo.org/glsa/201512-10" }, { "url" : "https://security.gentoo.org/glsa/201506-02" }, { "url" : "https://security.gentoo.org/glsa/201701-46" }, { "url" : "http://marc.info/?l=bugtraq&m=143880121627664&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143880121627664&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=145409266329539&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143557934009303&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143628304012255&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143558092609708&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143655800220052&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144060576831314&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144069189622016&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144050121701297&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144060606031437&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144102017024820&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144061542602287&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144043644216842&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143506486712441&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144104533800819&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=143637549705650&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144493176821532&w=2" }, { "url" : "http://marc.info/?l=bugtraq&m=144493176821532&w=2" }, { "url" : "https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04718196" }, { "url" : "http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1526.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1072.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1197.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1185.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1228.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1229.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1230.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1241.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1242.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1243.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1485.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1486.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1488.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1544.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2015-1604.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2016-1624.html" }, { "url" : "http://rhn.redhat.com/errata/RHSA-2016-2056.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.html" }, { "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00094.html" }, { "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00097.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.html" }, { "url" : "http://lists.opensuse.org/opensuse-updates/2015-10/msg00011.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00001.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" }, { "url" : "http://lists.opensuse.org/opensuse-updates/2015-07/msg00016.html" }, { "url" : "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html" }, { "url" : "http://www.ubuntu.com/usn/USN-2673-1" }, { "url" : "http://www.ubuntu.com/usn/USN-2696-1" }, { "url" : "http://www.ubuntu.com/usn/USN-2706-1" }, { "url" : "http://www.ubuntu.com/usn/USN-2656-1" }, { "url" : "http://www.ubuntu.com/usn/USN-2656-2" }, { "url" : "http://www.securityfocus.com/bid/74733" }, { "url" : "http://www.securityfocus.com/bid/91787" }, { "url" : "http://www.securitytracker.com/id/1033064" }, { "url" : "http://www.securitytracker.com/id/1034884" }, { "url" : "http://www.securitytracker.com/id/1034728" }, { "url" : "http://www.securitytracker.com/id/1033991" }, { "url" : "http://www.securitytracker.com/id/1034087" }, { "url" : "http://www.securitytracker.com/id/1033760" }, { "url" : "http://www.securitytracker.com/id/1033385" }, { "url" : "http://www.securitytracker.com/id/1033416" }, { "url" : "http://www.securitytracker.com/id/1033430" }, { "url" : "http://www.securitytracker.com/id/1033433" }, { "url" : "http://www.securitytracker.com/id/1033513" }, { "url" : "http://www.securitytracker.com/id/1033208" }, { "url" : "http://www.securitytracker.com/id/1033209" }, { "url" : "http://www.securitytracker.com/id/1033210" }, { "url" : "http://www.securitytracker.com/id/1033222" }, { "url" : "http://www.securitytracker.com/id/1033341" }, { "url" : "http://www.securitytracker.com/id/1033891" }, { "url" : "http://www.securitytracker.com/id/1032637" }, { "url" : "http://www.securitytracker.com/id/1032645" }, { "url" : "http://www.securitytracker.com/id/1032647" }, { "url" : "http://www.securitytracker.com/id/1032648" }, { "url" : "http://www.securitytracker.com/id/1032649" }, { "url" : "http://www.securitytracker.com/id/1032650" }, { "url" : "http://www.securitytracker.com/id/1032651" }, { "url" : "http://www.securitytracker.com/id/1032652" }, { "url" : "http://www.securitytracker.com/id/1032653" }, { "url" : "http://www.securitytracker.com/id/1032654" }, { "url" : "http://www.securitytracker.com/id/1032655" }, { "url" : "http://www.securitytracker.com/id/1032656" }, { "url" : "http://www.securitytracker.com/id/1032688" }, { "url" : "http://www.securitytracker.com/id/1032699" }, { "url" : "http://www.securitytracker.com/id/1032702" }, { "url" : "http://www.securitytracker.com/id/1032727" }, { "url" : "http://www.securitytracker.com/id/1032759" }, { "url" : "http://www.securitytracker.com/id/1032777" }, { "url" : "http://www.securitytracker.com/id/1032778" }, { "url" : "http://www.securitytracker.com/id/1032783" }, { "url" : "http://www.securitytracker.com/id/1032784" }, { "url" : "http://www.securitytracker.com/id/1032856" }, { "url" : "http://www.securitytracker.com/id/1032864" }, { "url" : "http://www.securitytracker.com/id/1032865" }, { "url" : "http://www.securitytracker.com/id/1032871" }, { "url" : "http://www.securitytracker.com/id/1032884" }, { "url" : "http://www.securitytracker.com/id/1032474" }, { "url" : "http://www.securitytracker.com/id/1032475" }, { "url" : "http://www.securitytracker.com/id/1032476" }, { "url" : "http://www.securitytracker.com/id/1036218" }, { "url" : "http://www.securitytracker.com/id/1033019" }, { "url" : "http://www.securitytracker.com/id/1033065" }, { "url" : "http://www.securitytracker.com/id/1033067" }, { "url" : "http://www.securitytracker.com/id/1032910" }, { "url" : "http://www.securitytracker.com/id/1032932" }, { "url" : "http://www.securitytracker.com/id/1032960" } ] } }