CVE-2010-4180

Source
https://cve.org/CVERecord?id=CVE-2010-4180
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2010-4180.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2010-4180
Downstream
Related
Withdrawn
2026-01-27T04:10:30Z
Published
2010-12-06T21:05:48Z
Modified
2026-01-27T04:10:30Z
Summary
[none]
Details

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

References

Affected packages