CVE-2011-3389

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
googlechrome
-
microsoftinternet_explorer
-
mozillafirefox
-
operaopera_browser
-
microsoftwindows
-
siemenssimatic_rf68xr_firmware
𝑥
< 3.2.1
siemenssimatic_rf615r_firmware
𝑥
< 3.2.1
haxxcurl
7.10.6 ≤
𝑥
≤ 7.23.1
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
6.2
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_aus
6.2
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
debiandebian_linux
5.0
debiandebian_linux
6.0
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
canonicalubuntu_linux
11.04
canonicalubuntu_linux
11.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
1:16.28.0~dfsg-0+deb11u4
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bullseye (security)
1:16.28.0~dfsg-0+deb11u5
fixed
sid
1:22.0.0~dfsg+~cs6.14.60671435-1
fixed
bouncycastle
bullseye
1.68-2
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bookworm
1.72-2
fixed
sid
1.77-1
fixed
trixie
1.77-1
fixed
curl
bullseye
7.74.0-1.3+deb11u13
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bullseye (security)
7.74.0-1.3+deb11u11
fixed
bookworm
7.88.1-10+deb12u7
fixed
bookworm (security)
7.88.1-10+deb12u5
fixed
sid
8.10.1-2
fixed
trixie
8.10.1-2
fixed
erlang
bullseye
1:23.2.6+dfsg-1+deb11u1
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bookworm
1:25.2.3+dfsg-1
fixed
sid
1:25.3.2.12+dfsg-3
fixed
trixie
1:25.3.2.12+dfsg-3
fixed
gnutls28
bullseye
unimportant
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bullseye (security)
unimportant
bookworm
unimportant
sid
unimportant
trixie
unimportant
haskell-tls
bullseye
unimportant
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bookworm
unimportant
sid
unimportant
trixie
unimportant
lighttpd
bullseye (security)
1.4.59-1+deb11u2
fixed
bullseye
1.4.59-1+deb11u2
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bookworm
1.4.69-1
fixed
sid
1.4.76-1
fixed
trixie
1.4.76-1
fixed
nss
bullseye
2:3.61-1+deb11u3
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
pound
bullseye
3.0-2
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
sid
4.14-2
fixed
trixie
4.14-2
fixed
python2.7
bullseye
2.7.18-8+deb11u1
fixed
lenny
no-dsa
squeeze
no-dsa
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls26
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
dne
icedtea-web
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
dne
lucid
not-affected
hardy
dne
lighttpd
quantal
ignored
precise
ignored
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
openjdk-6
quantal
not-affected
precise
not-affected
oneiric
Fixed 6b23~pre11-0ubuntu1.11.10
released
natty
Fixed 6b22-1.10.4-0ubuntu1~11.04.1
released
maverick
Fixed 6b20-1.9.10-0ubuntu1~10.10.2
released
lucid
Fixed 6b20-1.9.10-0ubuntu1~10.04.2
released
hardy
Fixed 6b27-1.12.3-0ubuntu1~08.04.1
released
openjdk-6b18
quantal
dne
precise
dne
oneiric
ignored
natty
Fixed 6b18-1.8.10-0ubuntu1~11.04.1
released
maverick
Fixed 6b18-1.8.10-0ubuntu1~10.10.2
released
lucid
Fixed 6b18-1.8.10-0ubuntu1~10.04.2
released
hardy
dne
openjdk-7
quantal
Fixed 7~b147-2.0-1ubuntu1
released
precise
Fixed 7~b147-2.0-1ubuntu1
released
oneiric
Fixed 7~b147-2.0-0ubuntu0.11.10.1
released
natty
dne
maverick
dne
lucid
dne
hardy
dne
openssl
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
not-affected
sun-java5
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
dne
hardy
ignored
sun-java6
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
dne
hardy
ignored
References