CVE-2010-4180

Source
https://nvd.nist.gov/vuln/detail/CVE-2010-4180
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2010-4180.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2010-4180
Downstream
Related
Published
2010-12-06T21:05:48Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSLOPNETSCAPEREUSECIPHERCHANGEBUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

References

Affected packages