{ "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2009-3555", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a \"plaintext injection\" attack, aka the \"Project Mogul\" issue." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "APPLE-SA-2010-05-18-1", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" }, { "name": "1023427", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023427" }, { "name": "http://support.avaya.com/css/P8/documents/100081611", "refsource": "CONFIRM", "url": "http://support.avaya.com/css/P8/documents/100081611" }, { "name": "62210", "refsource": "OSVDB", "url": "http://osvdb.org/62210" }, { "name": "37640", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37640" }, { "name": "http://www.arubanetworks.com/support/alerts/aid-020810.txt", "refsource": "CONFIRM", "url": "http://www.arubanetworks.com/support/alerts/aid-020810.txt" }, { "name": "ADV-2010-0916", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0916" }, { "name": "http://support.avaya.com/css/P8/documents/100114327", "refsource": "CONFIRM", "url": "http://support.avaya.com/css/P8/documents/100114327" }, { "name": "RHSA-2010:0167", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0167.html" }, { "name": "ADV-2010-2010", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/2010" }, { "name": "FEDORA-2009-12750", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html" }, { "name": "ADV-2010-0086", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0086" }, { "name": "ADV-2010-1673", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1673" }, { "name": "[tls] 20091104 TLS renegotiation issue", "refsource": "MLIST", "url": "http://www.ietf.org/mail-archive/web/tls/current/msg03948.html" }, { "name": "37656", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37656" }, { "name": "RHSA-2010:0865", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0865.html" }, { "name": "39628", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39628" }, { "name": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html", "refsource": "CONFIRM", "url": "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html" }, { "name": "42724", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42724" }, { "name": "ADV-2009-3310", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3310" }, { "name": "ADV-2009-3205", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3205" }, { "name": "http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during", "refsource": "CONFIRM", "url": "http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during" }, { "name": "39461", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39461" }, { "name": "http://support.avaya.com/css/P8/documents/100114315", "refsource": "CONFIRM", "url": "http://support.avaya.com/css/P8/documents/100114315" }, { "name": "http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c", "refsource": "CONFIRM", "url": "http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c" }, { "name": "GLSA-201406-32", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-201406-32.xml" }, { "name": "http://www.ingate.com/Relnote.php?ver=481", "refsource": "CONFIRM", "url": "http://www.ingate.com/Relnote.php?ver=481" }, { "name": "1023204", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023204" }, { "name": "40866", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40866" }, { "name": "HPSBMU02799", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=134254866602253&w=2" }, { "name": "TA10-222A", "refsource": "CERT", "url": "http://www.us-cert.gov/cas/techalerts/TA10-222A.html" }, { "name": "1023211", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023211" }, { "name": "SSRT090249", "refsource": "HP", "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686" }, { "name": "39317", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39317" }, { "name": "1023212", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023212" }, { "name": "SUSE-SA:2010:061", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html" }, { "name": "39127", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39127" }, { "name": "40545", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40545" }, { "name": "ADV-2010-3069", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/3069" }, { "name": "[4.5] 010: SECURITY FIX: November 26, 2009", "refsource": "OPENBSD", "url": "http://openbsd.org/errata45.html#010_openssl" }, { "name": "1023210", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023210" }, { "name": "1023270", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023270" }, { "name": "40070", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40070" }, { "name": "1023273", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023273" }, { "name": "http://kbase.redhat.com/faq/docs/DOC-20491", "refsource": "CONFIRM", "url": "http://kbase.redhat.com/faq/docs/DOC-20491" }, { "name": "USN-927-5", "refsource": "UBUNTU", "url": "http://www.ubuntu.com/usn/USN-927-5" }, { "name": "PM12247", "refsource": "AIXAPAR", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" }, { "name": "SUSE-SU-2011:0847", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html" }, { "name": "MDVSA-2010:089", "refsource": "MANDRIVA", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:089" }, { "name": "RHSA-2010:0770", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0770.html" }, { "name": "http://www.openssl.org/news/secadv_20091111.txt", "refsource": "CONFIRM", "url": "http://www.openssl.org/news/secadv_20091111.txt" }, { "name": "1023275", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023275" }, { "name": "DSA-3253", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2015/dsa-3253" }, { "name": "ADV-2009-3484", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3484" }, { "name": "1023207", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023207" }, { "name": "37859", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37859" }, { "name": "SSRT101846", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=142660345230545&w=2" }, { "name": "1021752", "refsource": "SUNALERT", "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1" }, { "name": "FEDORA-2010-6131", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html" }, { "name": "ADV-2010-0848", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0848" }, { "name": "[oss-security] 20091107 Re: [TLS] CVE-2009-3555 for TLS renegotiation MITM attacks", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/07/3" }, { "name": "39819", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39819" }, { "name": "IC68055", "refsource": "AIXAPAR", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055" }, { "name": "http://www.links.org/?p=786", "refsource": "MISC", "url": "http://www.links.org/?p=786" }, { "name": "60521", "refsource": "OSVDB", "url": "http://osvdb.org/60521" }, { "name": "[oss-security] 20091123 Re: CVEs for nginx", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/23/10" }, { "name": "VU#120541", "refsource": "CERT-VN", "url": "http://www.kb.cert.org/vuls/id/120541" }, { "name": "1023217", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023217" }, { "name": "RHSA-2010:0768", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0768.html" }, { "name": "ADV-2009-3353", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3353" }, { "name": "FEDORA-2010-5357", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html" }, { "name": "39136", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39136" }, { "name": "http://www.openoffice.org/security/cves/CVE-2009-3555.html", "refsource": "CONFIRM", "url": "http://www.openoffice.org/security/cves/CVE-2009-3555.html" }, { "name": "ADV-2011-0032", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2011/0032" }, { "name": "1023148", "refsource": "SECTRACK", "url": "http://securitytracker.com/id?1023148" }, { "name": "openSUSE-SU-2011:0845", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html" }, { "name": "36935", "refsource": "BID", "url": "http://www.securityfocus.com/bid/36935" }, { "name": "http://www.tombom.co.uk/blog/?p=85", "refsource": "MISC", "url": "http://www.tombom.co.uk/blog/?p=85" }, { "name": "SSRT090208", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=130497311408250&w=2" }, { "name": "ADV-2010-1107", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1107" }, { "name": "1023218", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023218" }, { "name": "ADV-2010-1350", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1350" }, { "name": "RHSA-2010:0338", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0338.html" }, { "name": "42379", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42379" }, { "name": "FEDORA-2009-12775", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html" }, { "name": "20091109 Transport Layer Security Renegotiation Vulnerability", "refsource": "CISCO", "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml" }, { "name": "IC67848", "refsource": "AIXAPAR", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848" }, { "name": "1023213", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023213" }, { "name": "FEDORA-2010-16240", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html" }, { "name": "ADV-2010-1793", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1793" }, { "name": "oval:org.mitre.oval:def:11617", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617" }, { "name": "http://extendedsubset.com/?p=8", "refsource": "MISC", "url": "http://extendedsubset.com/?p=8" }, { "name": "37292", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37292" }, { "name": "SSRT100817", "refsource": "HP", "url": "http://www.securityfocus.com/archive/1/522176" }, { "name": "tls-renegotiation-weak-security(54158)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54158" }, { "name": "APPLE-SA-2010-05-18-2", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" }, { "name": "39278", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39278" }, { "name": "1023205", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023205" }, { "name": "RHSA-2010:0130", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0130.html" }, { "name": "HPSBUX02482", "refsource": "HP", "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686" }, { "name": "HPSBHF03293", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=142660345230545&w=2" }, { "name": "http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html", "refsource": "CONFIRM", "url": "http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html" }, { "name": "http://support.apple.com/kb/HT4004", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT4004" }, { "name": "1023215", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023215" }, { "name": "USN-1010-1", "refsource": "UBUNTU", "url": "http://www.ubuntu.com/usn/USN-1010-1" }, { "name": "1023206", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023206" }, { "name": "SUSE-SR:2010:011", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" }, { "name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888", "refsource": "CONFIRM", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888" }, { "name": "GLSA-200912-01", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-200912-01.xml" }, { "name": "SSRT090180", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127419602507642&w=2" }, { "name": "ADV-2009-3313", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3313" }, { "name": "274990", "refsource": "SUNALERT", "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1" }, { "name": "1023208", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023208" }, { "name": "43308", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/43308" }, { "name": "1023214", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023214" }, { "name": "SUSE-SA:2009:057", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html" }, { "name": "38781", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38781" }, { "name": "HPSBOV02762", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=133469267822771&w=2" }, { "name": "HPSBMA02534", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127419602507642&w=2" }, { "name": "DSA-1934", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2009/dsa-1934" }, { "name": "FEDORA-2009-12782", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html" }, { "name": "oval:org.mitre.oval:def:7478", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478" }, { "name": "1023271", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023271" }, { "name": "APPLE-SA-2010-01-19-1", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html" }, { "name": "[cryptography] 20091105 OpenSSL 0.9.8l released", "refsource": "MLIST", "url": "http://marc.info/?l=cryptography&m=125752275331877&w=2" }, { "name": "42467", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42467" }, { "name": "20091130 TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/508130/100/0/threaded" }, { "name": "oval:org.mitre.oval:def:7315", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315" }, { "name": "1023224", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023224" }, { "name": "SUSE-SR:2010:013", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" }, { "name": "USN-927-4", "refsource": "UBUNTU", "url": "http://www.ubuntu.com/usn/USN-927-4" }, { "name": "41490", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/41490" }, { "name": "20091124 rPSA-2009-0155-1 httpd mod_ssl", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/508075/100/0/threaded" }, { "name": "1023243", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023243" }, { "name": "http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html", "refsource": "MISC", "url": "http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html" }, { "name": "37504", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37504" }, { "name": "1023219", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023219" }, { "name": "http://sysoev.ru/nginx/patch.cve-2009-3555.txt", "refsource": "CONFIRM", "url": "http://sysoev.ru/nginx/patch.cve-2009-3555.txt" }, { "name": "http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html", "refsource": "MISC", "url": "http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html" }, { "name": "1023163", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023163" }, { "name": "HPSBHF02706", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=132077688910227&w=2" }, { "name": "ADV-2009-3521", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3521" }, { "name": "oval:org.mitre.oval:def:7973", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973" }, { "name": "HPSBMA02568", "refsource": "HP", "url": "http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995" }, { "name": "http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released", "refsource": "CONFIRM", "url": "http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=533125", "refsource": "CONFIRM", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=533125" }, { "name": "oval:org.mitre.oval:def:10088", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088" }, { "name": "44183", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/44183" }, { "name": "http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES", "refsource": "CONFIRM", "url": "http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES" }, { "name": "42808", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42808" }, { "name": "39500", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39500" }, { "name": "oval:org.mitre.oval:def:11578", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578" }, { "name": "http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html", "refsource": "CONFIRM", "url": "http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" }, { "name": "ADV-2009-3220", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3220" }, { "name": "SSRT100179", "refsource": "HP", "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" }, { "name": "SSRT100089", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127557596201693&w=2" }, { "name": "RHSA-2010:0165", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0165.html" }, { "name": "20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/515055/100/0/threaded" }, { "name": "RHSA-2010:0987", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0987.html" }, { "name": "https://bugzilla.mozilla.org/show_bug.cgi?id=545755", "refsource": "CONFIRM", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=545755" }, { "name": "http://www-01.ibm.com/support/docview.wss?uid=swg21426108", "refsource": "CONFIRM", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21426108" }, { "name": "http://blogs.iss.net/archive/sslmitmiscsrf.html", "refsource": "MISC", "url": "http://blogs.iss.net/archive/sslmitmiscsrf.html" }, { "name": "1023411", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023411" }, { "name": "RHSA-2010:0339", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0339.html" }, { "name": "RHSA-2010:0986", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0986.html" }, { "name": "ADV-2009-3164", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3164" }, { "name": "37383", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37383" }, { "name": "FEDORA-2009-12229", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html" }, { "name": "44954", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/44954" }, { "name": "[tls] 20091104 MITM attack on delayed TLS-client auth through renegotiation", "refsource": "MLIST", "url": "http://www.ietf.org/mail-archive/web/tls/current/msg03928.html" }, { "name": "HPSBUX02524", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127557596201693&w=2" }, { "name": "http://support.avaya.com/css/P8/documents/100070150", "refsource": "CONFIRM", "url": "http://support.avaya.com/css/P8/documents/100070150" }, { "name": "40747", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40747" }, { "name": "HPSBUX02498", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=126150535619567&w=2" }, { "name": "HPSBMU02759", "refsource": "HP", "url": "http://www.securityfocus.com/archive/1/522176" }, { "name": "39292", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39292" }, { "name": "42816", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42816" }, { "name": "IC68054", "refsource": "AIXAPAR", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054" }, { "name": "273029", "refsource": "SUNALERT", "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1" }, { "name": "FEDORA-2009-12604", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html" }, { "name": "http://www-01.ibm.com/support/docview.wss?uid=swg21432298", "refsource": "CONFIRM", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21432298" }, { "name": "http://extendedsubset.com/Renegotiating_TLS.pdf", "refsource": "MISC", "url": "http://extendedsubset.com/Renegotiating_TLS.pdf" }, { "name": "http://www-01.ibm.com/support/docview.wss?uid=swg24025312", "refsource": "CONFIRM", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg24025312" }, { "name": "http://www-01.ibm.com/support/docview.wss?uid=swg24006386", "refsource": "CONFIRM", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg24006386" }, { "name": "http://support.apple.com/kb/HT4170", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT4170" }, { "name": "20091118 TLS / SSLv3 vulnerability explained (DRAFT)", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/507952/100/0/threaded" }, { "name": "1023209", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023209" }, { "name": "PM00675", "refsource": "AIXAPAR", "url": "http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only" }, { "name": "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html", "refsource": "CONFIRM", "url": "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" }, { "name": "HPSBOV02683", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=130497311408250&w=2" }, { "name": "48577", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/48577" }, { "name": "SSA:2009-320-01", "refsource": "SLACKWARE", "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446" }, { "name": "http://www.links.org/?p=789", "refsource": "MISC", "url": "http://www.links.org/?p=789" }, { "name": "http://www.opera.com/docs/changelogs/unix/1060/", "refsource": "CONFIRM", "url": "http://www.opera.com/docs/changelogs/unix/1060/" }, { "name": "http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html", "refsource": "MISC", "url": "http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html" }, { "name": "RHSA-2011:0880", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2011-0880.html" }, { "name": "SUSE-SR:2010:008", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" }, { "name": "http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html", "refsource": "CONFIRM", "url": "http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html" }, { "name": "[oss-security] 20091107 Re: CVE-2009-3555 for TLS renegotiation MITM attacks", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/06/3" }, { "name": "FEDORA-2009-12305", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html" }, { "name": "http://wiki.rpath.com/Advisories:rPSA-2009-0155", "refsource": "CONFIRM", "url": "http://wiki.rpath.com/Advisories:rPSA-2009-0155" }, { "name": "SUSE-SR:2010:012", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" }, { "name": "http://support.citrix.com/article/CTX123359", "refsource": "CONFIRM", "url": "http://support.citrix.com/article/CTX123359" }, { "name": "37501", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37501" }, { "name": "MDVSA-2010:076", "refsource": "MANDRIVA", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:076" }, { "name": "HPSBUX02517", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127128920008563&w=2" }, { "name": "ADV-2009-3587", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3587" }, { "name": "39632", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39632" }, { "name": "SSRT090264", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=126150535619567&w=2" }, { "name": "38687", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38687" }, { "name": "https://bugzilla.mozilla.org/show_bug.cgi?id=526689", "refsource": "MISC", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=526689" }, { "name": "MS10-049", "refsource": "MS", "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049" }, { "name": "ADV-2010-0982", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0982" }, { "name": "SSRT100825", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=133469267822771&w=2" }, { "name": "37399", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37399" }, { "name": "USN-927-1", "refsource": "UBUNTU", "url": "http://www.ubuntu.com/usn/USN-927-1" }, { "name": "1023272", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023272" }, { "name": "FEDORA-2009-12606", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html" }, { "name": "ADV-2010-3126", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/3126" }, { "name": "37320", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37320" }, { "name": "ADV-2009-3165", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3165" }, { "name": "ADV-2010-1639", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1639" }, { "name": "38020", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38020" }, { "name": "USN-923-1", "refsource": "UBUNTU", "url": "http://ubuntu.com/usn/usn-923-1" }, { "name": "39243", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39243" }, { "name": "oval:org.mitre.oval:def:8366", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366" }, { "name": "37453", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37453" }, { "name": "http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html", "refsource": "CONFIRM", "url": "http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html" }, { "name": "ADV-2010-0933", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0933" }, { "name": "SSRT100219", "refsource": "HP", "url": "http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995" }, { "name": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html", "refsource": "CONFIRM", "url": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html" }, { "name": "41972", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/41972" }, { "name": "ADV-2010-3086", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/3086" }, { "name": "DSA-2141", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2011/dsa-2141" }, { "name": "1024789", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1024789" }, { "name": "RHSA-2010:0155", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0155.html" }, { "name": "http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html", "refsource": "MISC", "url": "http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html" }, { "name": "ADV-2011-0033", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2011/0033" }, { "name": "RHSA-2010:0337", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0337.html" }, { "name": "1023216", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023216" }, { "name": "41480", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/41480" }, { "name": "ADV-2011-0086", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2011/0086" }, { "name": "41818", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/41818" }, { "name": "37604", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37604" }, { "name": "http://www.opera.com/support/search/view/944/", "refsource": "CONFIRM", "url": "http://www.opera.com/support/search/view/944/" }, { "name": "[announce] 20091107 CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation", "refsource": "MLIST", "url": "http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2" }, { "name": "SUSE-SR:2010:024", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" }, { "name": "TA10-287A", "refsource": "CERT", "url": "http://www.us-cert.gov/cas/techalerts/TA10-287A.html" }, { "name": "http://www.links.org/?p=780", "refsource": "MISC", "url": "http://www.links.org/?p=780" }, { "name": "RHSA-2010:0119", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0119.html" }, { "name": "38056", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38056" }, { "name": "ADV-2010-0748", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0748" }, { "name": "37675", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37675" }, { "name": "oval:org.mitre.oval:def:8535", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535" }, { "name": "HPSBMA02547", "refsource": "HP", "url": "http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" }, { "name": "SSRT100058", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=127128920008563&w=2" }, { "name": "http://www.vmware.com/security/advisories/VMSA-2010-0019.html", "refsource": "CONFIRM", "url": "http://www.vmware.com/security/advisories/VMSA-2010-0019.html" }, { "name": "RHSA-2010:0786", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0786.html" }, { "name": "https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt", "refsource": "MISC", "url": "https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt" }, { "name": "38003", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38003" }, { "name": "http://support.apple.com/kb/HT4171", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT4171" }, { "name": "1023428", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023428" }, { "name": "SSRT100613", "refsource": "HP", "url": "http://marc.info/?l=bugtraq&m=132077688910227&w=2" }, { "name": "[oss-security] 20091120 CVEs for nginx", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/20/1" }, { "name": "ADV-2009-3354", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3354" }, { "name": "1023274", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023274" }, { "name": "FEDORA-2009-12968", "refsource": "FEDORA", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html" }, { "name": "39242", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39242" }, { "name": "https://kb.bluecoat.com/index?page=content&id=SA50", "refsource": "CONFIRM", "url": "https://kb.bluecoat.com/index?page=content&id=SA50" }, { "name": "38241", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38241" }, { "name": "42377", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42377" }, { "name": "GLSA-201203-22", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-201203-22.xml" }, { "name": "[oss-security] 20091105 CVE-2009-3555 for TLS renegotiation MITM attacks", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/05/3" }, { "name": "SUSE-SR:2010:019", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" }, { "name": "60972", "refsource": "OSVDB", "url": "http://osvdb.org/60972" }, { "name": "1023426", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id?1023426" }, { "name": "38484", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38484" }, { "name": "MDVSA-2010:084", "refsource": "MANDRIVA", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" }, { "name": "http://www.betanews.com/article/1257452450", "refsource": "MISC", "url": "http://www.betanews.com/article/1257452450" }, { "name": "1021653", "refsource": "SUNALERT", "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1" }, { "name": "http://www.mozilla.org/security/announce/2010/mfsa2010-22.html", "refsource": "CONFIRM", "url": "http://www.mozilla.org/security/announce/2010/mfsa2010-22.html" }, { "name": "20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded" }, { "name": "[4.6] 004: SECURITY FIX: November 26, 2009", "refsource": "OPENBSD", "url": "http://openbsd.org/errata46.html#004_openssl" }, { "name": "41967", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/41967" }, { "name": "RHSA-2010:0807", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0807.html" }, { "name": "ADV-2010-1191", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1191" }, { "name": "20091111 Re: SSL/TLS MiTM PoC", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2009/Nov/139" }, { "name": "https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html", "refsource": "MISC", "url": "https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html" }, { "name": "[oss-security] 20091105 Re: CVE-2009-3555 for TLS renegotiation MITM attacks", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2009/11/05/5" }, { "name": "39713", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/39713" }, { "name": "42733", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42733" }, { "name": "37291", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/37291" }, { "name": "FEDORA-2010-16312", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html" }, { "name": "FEDORA-2010-5942", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html" }, { "name": "ADV-2010-2745", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/2745" }, { "name": "273350", "refsource": "SUNALERT", "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1" }, { "name": "ADV-2010-0994", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0994" }, { "name": "ADV-2010-0173", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/0173" }, { "name": "ADV-2010-1054", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1054" }, { "name": "65202", "refsource": "OSVDB", "url": "http://osvdb.org/65202" }, { "name": "HPSBGN02562", "refsource": "HP", "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041" }, { "name": "FEDORA-2010-16294", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html" }, { "name": "[gnutls-devel] 20091105 Re: TLS renegotiation MITM", "refsource": "MLIST", "url": "http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html" }, { "name": "20131121 ESA-2013-077: RSA Data Protection Manager Appliance Multiple Vulnerabilities", "refsource": "BUGTRAQ", "url": "http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html" }, { "name": "http://clicky.me/tlsvuln", "refsource": "MISC", "url": "http://clicky.me/tlsvuln" }, { "name": "42811", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/42811" }, { "refsource": "MLIST", "name": "[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/", "url": "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E" }, { "refsource": "MLIST", "name": "[tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/", "url": "https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2@%3Cdev.tomcat.apache.org%3E" } ] } }