CVE Database
/

CVE-2015-3197

Back to search

CVE-2015-3197

Published: Feb 15, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2016-527018d2ff
vendor-advisory
openSUSE-SU-2016:0638
vendor-advisory
openSUSE-SU-2016:1239
vendor-advisory
SUSE-SU-2016:0621
vendor-advisory
1034849
vdb-entry
openSUSE-SU-2016:0640
vendor-advisory
SUSE-SU-2016:1057
vendor-advisory
GLSA-201601-05
vendor-advisory
openSUSE-SU-2016:1241
vendor-advisory
openSUSE-SU-2016:0720
vendor-advisory
SUSE-SU-2016:0624
vendor-advisory
SUSE-SU-2016:0631
vendor-advisory
91787
vdb-entry
SUSE-SU-2016:0617
vendor-advisory
VU#257823
third-party-advisory
openSUSE-SU-2016:0628
vendor-advisory
82237
vdb-entry
SUSE-SU-2016:0678
vendor-advisory
SUSE-SU-2016:0620
vendor-advisory
openSUSE-SU-2016:0637
vendor-advisory
SUSE-SU-2016:0641
vendor-advisory
FreeBSD-SA-16:11
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now