CVE-2014-3566
15.10.2014, 00:55
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_desktop_supplementary | 5.0 |
| redhat | enterprise_linux_desktop_supplementary | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_supplementary | 5.0 |
| redhat | enterprise_linux_server_supplementary | 6.0 |
| redhat | enterprise_linux_server_supplementary | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_workstation_supplementary | 6.0 |
| redhat | enterprise_linux_workstation_supplementary | 7.0 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
| apple | mac_os_x | 𝑥 ≤ 10.10.1 |
| mageia | mageia | 3.0 |
| mageia | mageia | 4.0 |
| novell | suse_linux_enterprise_desktop | 9.0 |
| novell | suse_linux_enterprise_desktop | 10.0 |
| novell | suse_linux_enterprise_desktop | 11.0 |
| novell | suse_linux_enterprise_desktop | 12.0 |
| novell | suse_linux_enterprise_software_development_kit | 11.0:sp3 |
| novell | suse_linux_enterprise_software_development_kit | 12.0 |
| novell | suse_linux_enterprise_server | 11.0:sp3 |
| novell | suse_linux_enterprise_server | 11.0:sp3 |
| novell | suse_linux_enterprise_server | 12.0 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| openssl | openssl | 0.9.8 |
| openssl | openssl | 0.9.8a:a |
| openssl | openssl | 0.9.8b:b |
| openssl | openssl | 0.9.8c:c |
| openssl | openssl | 0.9.8d:d |
| openssl | openssl | 0.9.8e:e |
| openssl | openssl | 0.9.8f:f |
| openssl | openssl | 0.9.8g:g |
| openssl | openssl | 0.9.8h:h |
| openssl | openssl | 0.9.8i:i |
| openssl | openssl | 0.9.8j:j |
| openssl | openssl | 0.9.8k:k |
| openssl | openssl | 0.9.8l:l |
| openssl | openssl | 0.9.8m:m |
| openssl | openssl | 0.9.8m:m |
| openssl | openssl | 0.9.8n:n |
| openssl | openssl | 0.9.8o:o |
| openssl | openssl | 0.9.8p:p |
| openssl | openssl | 0.9.8q:q |
| openssl | openssl | 0.9.8r:r |
| openssl | openssl | 0.9.8s:s |
| openssl | openssl | 0.9.8t:t |
| openssl | openssl | 0.9.8u:u |
| openssl | openssl | 0.9.8v:v |
| openssl | openssl | 0.9.8w:w |
| openssl | openssl | 0.9.8x:x |
| openssl | openssl | 0.9.8y:y |
| openssl | openssl | 0.9.8z:z |
| openssl | openssl | 0.9.8za:za |
| openssl | openssl | 0.9.8zb:zb |
| openssl | openssl | 1.0.0 |
| openssl | openssl | 1.0.0:beta1 |
| openssl | openssl | 1.0.0:beta2 |
| openssl | openssl | 1.0.0:beta3 |
| openssl | openssl | 1.0.0:beta4 |
| openssl | openssl | 1.0.0:beta5 |
| openssl | openssl | 1.0.0a:a |
| openssl | openssl | 1.0.0b:b |
| openssl | openssl | 1.0.0c:c |
| openssl | openssl | 1.0.0d:d |
| openssl | openssl | 1.0.0e:e |
| openssl | openssl | 1.0.0f:f |
| openssl | openssl | 1.0.0g:g |
| openssl | openssl | 1.0.0h:h |
| openssl | openssl | 1.0.0i:i |
| openssl | openssl | 1.0.0j:j |
| openssl | openssl | 1.0.0k:k |
| openssl | openssl | 1.0.0l:l |
| openssl | openssl | 1.0.0m:m |
| openssl | openssl | 1.0.0n:n |
| openssl | openssl | 1.0.1 |
| openssl | openssl | 1.0.1:beta1 |
| openssl | openssl | 1.0.1:beta2 |
| openssl | openssl | 1.0.1:beta3 |
| openssl | openssl | 1.0.1a:a |
| openssl | openssl | 1.0.1b:b |
| openssl | openssl | 1.0.1c:c |
| openssl | openssl | 1.0.1d:d |
| openssl | openssl | 1.0.1e:e |
| openssl | openssl | 1.0.1f:f |
| openssl | openssl | 1.0.1g:g |
| openssl | openssl | 1.0.1h:h |
| openssl | openssl | 1.0.1i:i |
| ibm | vios | 2.2.0.10 |
| ibm | vios | 2.2.0.11 |
| ibm | vios | 2.2.0.12 |
| ibm | vios | 2.2.0.13 |
| ibm | vios | 2.2.1.0 |
| ibm | vios | 2.2.1.1 |
| ibm | vios | 2.2.1.3 |
| ibm | vios | 2.2.1.4 |
| ibm | vios | 2.2.1.5 |
| ibm | vios | 2.2.1.6 |
| ibm | vios | 2.2.1.7 |
| ibm | vios | 2.2.1.8 |
| ibm | vios | 2.2.1.9 |
| ibm | vios | 2.2.2.0 |
| ibm | vios | 2.2.2.1 |
| ibm | vios | 2.2.2.2 |
| ibm | vios | 2.2.2.3 |
| ibm | vios | 2.2.2.4 |
| ibm | vios | 2.2.2.5 |
| ibm | vios | 2.2.3.0 |
| ibm | vios | 2.2.3.1 |
| ibm | vios | 2.2.3.2 |
| ibm | vios | 2.2.3.3 |
| ibm | vios | 2.2.3.4 |
| netbsd | netbsd | 5.1 |
| netbsd | netbsd | 5.1.1 |
| netbsd | netbsd | 5.1.2 |
| netbsd | netbsd | 5.1.3 |
| netbsd | netbsd | 5.1.4 |
| netbsd | netbsd | 5.2 |
| netbsd | netbsd | 5.2.1 |
| netbsd | netbsd | 5.2.2 |
| netbsd | netbsd | 6.0 |
| netbsd | netbsd | 6.0:beta |
| netbsd | netbsd | 6.0.1 |
| netbsd | netbsd | 6.0.2 |
| netbsd | netbsd | 6.0.3 |
| netbsd | netbsd | 6.0.4 |
| netbsd | netbsd | 6.0.5 |
| netbsd | netbsd | 6.0.6 |
| netbsd | netbsd | 6.1 |
| netbsd | netbsd | 6.1.1 |
| netbsd | netbsd | 6.1.2 |
| netbsd | netbsd | 6.1.3 |
| netbsd | netbsd | 6.1.4 |
| netbsd | netbsd | 6.1.5 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| oracle | database | 11.2.0.4 |
| oracle | database | 12.1.0.2 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bouncycastle |
| ||||||||||||||||
| epiphany-browser |
| ||||||||||||||||
| erlang |
| ||||||||||||||||
| gnutls28 |
| ||||||||||||||||
| haskell-tls |
| ||||||||||||||||
| lighttpd |
| ||||||||||||||||
| midori |
| ||||||||||||||||
| netsurf |
| ||||||||||||||||
| nss |
| ||||||||||||||||
| openjdk-8 |
| ||||||||||||||||
| openssl |
| ||||||||||||||||
| pound |
| ||||||||||||||||
| surf |
| ||||||||||||||||
| wolfssl |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| nss |
| ||||||||||||||||||||||||||||||||||||||
| openjdk-6 |
| ||||||||||||||||||||||||||||||||||||||
| openjdk-7 |
| ||||||||||||||||||||||||||||||||||||||
| openssl |
| ||||||||||||||||||||||||||||||||||||||
| openssl098 |
| ||||||||||||||||||||||||||||||||||||||
| pound |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| PackageKit-gstreamer-plugin |
| ||||||||
| evolution-data-server |
| ||||||||
| evolution-data-server-lang |
| ||||||||
| libZXing1 |
| ||||||||
| libcamel-1_2-45 |
| ||||||||
| libcamel-1_2-45-32bit |
| ||||||||
| libebackend-1_2-7 |
| ||||||||
| libebackend-1_2-7-32bit |
| ||||||||
| libebook-1_2-14 |
| ||||||||
| libebook-1_2-14-32bit |
| ||||||||
| libebook-contacts-1_2-0 |
| ||||||||
| libebook-contacts-1_2-0-32bit |
| ||||||||
| libecal-1_2-16 |
| ||||||||
| libecal-1_2-16-32bit |
| ||||||||
| libedata-book-1_2-20 |
| ||||||||
| libedata-book-1_2-20-32bit |
| ||||||||
| libedata-cal-1_2-23 |
| ||||||||
| libedata-cal-1_2-23-32bit |
| ||||||||
| libedataserver-1_2-18 |
| ||||||||
| libedataserver-1_2-18-32bit |
| ||||||||
| libreoffice |
| ||||||||
| libreoffice-base |
| ||||||||
| libreoffice-base-drivers-postgresql |
| ||||||||
| libreoffice-branding-upstream |
| ||||||||
| libreoffice-calc |
| ||||||||
| libreoffice-calc-extensions |
| ||||||||
| libreoffice-draw |
| ||||||||
| libreoffice-filters-optional |
| ||||||||
| libreoffice-gnome |
| ||||||||
| libreoffice-gtk3 |
| ||||||||
| libreoffice-icon-themes |
| ||||||||
| libreoffice-impress |
| ||||||||
| libreoffice-l10n-af |
| ||||||||
| libreoffice-l10n-ar |
| ||||||||
| libreoffice-l10n-bg |
| ||||||||
| libreoffice-l10n-ca |
| ||||||||
| libreoffice-l10n-cs |
| ||||||||
| libreoffice-l10n-da |
| ||||||||
| libreoffice-l10n-de |
| ||||||||
| libreoffice-l10n-en |
| ||||||||
| libreoffice-l10n-es |
| ||||||||
| libreoffice-l10n-fi |
| ||||||||
| libreoffice-l10n-fr |
| ||||||||
| libreoffice-l10n-gu |
| ||||||||
| libreoffice-l10n-hi |
| ||||||||
| libreoffice-l10n-hr |
| ||||||||
| libreoffice-l10n-hu |
| ||||||||
| libreoffice-l10n-it |
| ||||||||
| libreoffice-l10n-ja |
| ||||||||
| libreoffice-l10n-ko |
| ||||||||
| libreoffice-l10n-lt |
| ||||||||
| libreoffice-l10n-nb |
| ||||||||
| libreoffice-l10n-nl |
| ||||||||
| libreoffice-l10n-nn |
| ||||||||
| libreoffice-l10n-pl |
| ||||||||
| libreoffice-l10n-pt_BR |
| ||||||||
| libreoffice-l10n-pt_PT |
| ||||||||
| libreoffice-l10n-ro |
| ||||||||
| libreoffice-l10n-ru |
| ||||||||
| libreoffice-l10n-sk |
| ||||||||
| libreoffice-l10n-sv |
| ||||||||
| libreoffice-l10n-uk |
| ||||||||
| libreoffice-l10n-xh |
| ||||||||
| libreoffice-l10n-zh_CN |
| ||||||||
| libreoffice-l10n-zh_TW |
| ||||||||
| libreoffice-l10n-zu |
| ||||||||
| libreoffice-librelogo |
| ||||||||
| libreoffice-mailmerge |
| ||||||||
| libreoffice-math |
| ||||||||
| libreoffice-officebean |
| ||||||||
| libreoffice-pyuno |
| ||||||||
| libreoffice-writer |
| ||||||||
| libreoffice-writer-extensions |
| ||||||||
| libserf-1-1 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| java-1.5.0-ibm |
| ||||
| java-1.5.0-ibm-demo |
| ||||
| java-1.5.0-ibm-devel |
| ||||
| java-1.5.0-ibm-javacomm |
| ||||
| java-1.5.0-ibm-jdbc |
| ||||
| java-1.5.0-ibm-plugin |
| ||||
| java-1.5.0-ibm-src |
| ||||
| java-1.6.0-ibm |
| ||||
| java-1.6.0-ibm-demo |
| ||||
| java-1.6.0-ibm-devel |
| ||||
| java-1.6.0-ibm-javacomm |
| ||||
| java-1.6.0-ibm-jdbc |
| ||||
| java-1.6.0-ibm-plugin |
| ||||
| java-1.6.0-ibm-src |
| ||||
| java-1.6.0-openjdk |
| ||||
| java-1.6.0-openjdk-demo |
| ||||
| java-1.6.0-openjdk-devel |
| ||||
| java-1.6.0-openjdk-javadoc |
| ||||
| java-1.6.0-openjdk-src |
| ||||
| java-1.7.0-ibm |
| ||||
| java-1.7.0-ibm-demo |
| ||||
| java-1.7.0-ibm-devel |
| ||||
| java-1.7.0-ibm-jdbc |
| ||||
| java-1.7.0-ibm-plugin |
| ||||
| java-1.7.0-ibm-src |
| ||||
| java-1.7.0-openjdk |
| ||||
| java-1.7.0-openjdk-accessibility |
| ||||
| java-1.7.0-openjdk-demo |
| ||||
| java-1.7.0-openjdk-devel |
| ||||
| java-1.7.0-openjdk-headless |
| ||||
| java-1.7.0-openjdk-javadoc |
| ||||
| java-1.7.0-openjdk-src |
| ||||
| java-1.7.1-ibm |
| ||||
| java-1.7.1-ibm-demo |
| ||||
| java-1.7.1-ibm-devel |
| ||||
| java-1.7.1-ibm-jdbc |
| ||||
| java-1.7.1-ibm-plugin |
| ||||
| java-1.7.1-ibm-src |
| ||||
| java-1.8.0-openjdk |
| ||||
| java-1.8.0-openjdk-demo |
| ||||
| java-1.8.0-openjdk-devel |
| ||||
| java-1.8.0-openjdk-headless |
| ||||
| java-1.8.0-openjdk-javadoc |
| ||||
| java-1.8.0-openjdk-src |
| ||||
| nspr |
| ||||
| nspr-devel |
| ||||
| nss |
| ||||
| nss-devel |
| ||||
| nss-pkcs11-devel |
| ||||
| nss-softokn |
| ||||
| nss-softokn-devel |
| ||||
| nss-softokn-freebl |
| ||||
| nss-softokn-freebl-devel |
| ||||
| nss-sysinit |
| ||||
| nss-tools |
| ||||
| nss-util |
| ||||
| nss-util-devel |
|
Common Weakness Enumeration