An oracle protection mechanism in the getclientmasterkey function in s2srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.9.8ze"
},
{
"last_affected": "1.0.0"
},
{
"last_affected": "1.0.0-beta1"
},
{
"last_affected": "1.0.0-beta2"
},
{
"last_affected": "1.0.0-beta3"
},
{
"last_affected": "1.0.0-beta4"
},
{
"last_affected": "1.0.0-beta5"
},
{
"last_affected": "1.0.0a"
},
{
"last_affected": "1.0.0b"
},
{
"last_affected": "1.0.0c"
},
{
"last_affected": "1.0.0d"
},
{
"last_affected": "1.0.0e"
},
{
"last_affected": "1.0.0f"
},
{
"last_affected": "1.0.0g"
},
{
"last_affected": "1.0.0h"
},
{
"last_affected": "1.0.0i"
},
{
"last_affected": "1.0.0j"
},
{
"last_affected": "1.0.0k"
},
{
"last_affected": "1.0.0l"
},
{
"last_affected": "1.0.0m"
},
{
"last_affected": "1.0.0n"
},
{
"last_affected": "1.0.0o"
},
{
"last_affected": "1.0.0p"
},
{
"last_affected": "1.0.0q"
},
{
"last_affected": "1.0.1"
},
{
"last_affected": "1.0.1-beta1"
},
{
"last_affected": "1.0.1-beta2"
},
{
"last_affected": "1.0.1-beta3"
},
{
"last_affected": "1.0.1a"
},
{
"last_affected": "1.0.1b"
},
{
"last_affected": "1.0.1c"
},
{
"last_affected": "1.0.1d"
},
{
"last_affected": "1.0.1e"
},
{
"last_affected": "1.0.1f"
},
{
"last_affected": "1.0.1g"
},
{
"last_affected": "1.0.1h"
},
{
"last_affected": "1.0.1i"
},
{
"last_affected": "1.0.1j"
},
{
"last_affected": "1.0.1k"
},
{
"last_affected": "1.0.1l"
},
{
"last_affected": "1.0.2"
},
{
"last_affected": "1.0.2-beta1"
},
{
"last_affected": "1.0.2-beta2"
},
{
"last_affected": "1.0.2-beta3"
}
],
"cpe": [
"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0p:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.0q:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*",
"cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
]
}