CVE-2015-2808

EUVD-2015-2896
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
oraclecommunications_application_session_controller
3.0.0 ≤
𝑥
≤ 3.9.0
oraclecommunications_policy_management
𝑥
< 9.9.2
oraclehttp_server
11.1.1.7.0
oraclehttp_server
11.1.1.9.0
oraclehttp_server
12.1.3.0.0
oraclehttp_server
12.2.1.1.0
oraclehttp_server
12.2.1.2.0
oracleintegrated_lights_out_manager_firmware
3.0.0 ≤
𝑥
≤ 3.2.11
oracleintegrated_lights_out_manager_firmware
4.0.0 ≤
𝑥
≤ 4.0.4
debiandebian_linux
7.0
debiandebian_linux
8.0
redhatsatellite
5.7
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
6.6
redhatenterprise_linux_eus
7.1
redhatenterprise_linux_eus
7.2
redhatenterprise_linux_eus
7.3
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
6.6
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
opensuseopensuse
13.1
opensuseopensuse
13.2
susemanager
1.7
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
redhatsatellite
5.6
huaweie6000_firmware
-
huaweie9000_firmware
-
huaweioceanstor_18500_firmware
-
huaweioceanstor_18800_firmware
-
huaweioceanstor_18800f_firmware
-
huaweioceanstor_9000_firmware
-
huaweioceanstor_cse_firmware
-
huaweioceanstor_hvs85t_firmware
-
huaweioceanstor_s2600t_firmware
-
huaweioceanstor_s5500t_firmware
-
huaweioceanstor_s5600t_firmware
-
huaweioceanstor_s5800t_firmware
-
huaweioceanstor_s6800t_firmware
-
huaweioceanstor_vis6600t_firmware
-
huaweiquidway_s9300_firmware
-
huaweis7700_firmware
-
huaweis7700_firmware
-
huawei9700_firmware
-
huawei9700_firmware
-
huaweis12700_firmware
-
huaweis12700_firmware
-
huaweis2700_firmware
-
huaweis3700_firmware
-
huaweis5700ei_firmware
-
huaweis5700hi_firmware
-
huaweis5700si_firmware
-
huaweis5710ei_firmware
-
huaweis5710hi_firmware
-
huaweis6700_firmware
-
huaweis2750_firmware
-
huaweis5700li_firmware
-
huaweis5700s-li_firmware
-
huaweis5720hi_firmware
-
huaweis2750_firmware
-
huaweis5700li_firmware
-
huaweis5700s-li_firmware
-
huaweis5720hi_firmware
-
huaweis5720ei_firmware
-
huaweite60_firmware
-
ibmcognos_metrics_manager
10.1
ibmcognos_metrics_manager
10.1.1
ibmcognos_metrics_manager
10.2
ibmcognos_metrics_manager
10.2.1
ibmcognos_metrics_manager
10.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openjdk-8
sid
8u432-b06-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
precise
Fixed 6b36-1.13.8-0ubuntu1~12.04
released
trusty
Fixed 6b36-1.13.8-0ubuntu1~14.04
released
utopic
ignored
vivid
Fixed 6b36-1.13.8-0ubuntu1~15.04.1
released
wily
not-affected
openjdk-7
precise
Fixed 7u79-2.5.6-0ubuntu1.12.04.1
released
trusty
Fixed 7u79-2.5.6-0ubuntu1.14.04.1
released
utopic
ignored
vivid
Fixed 7u79-2.5.6-0ubuntu1.15.04.1
released
wily
not-affected
openjdk-8
precise
dne
trusty
dne
utopic
ignored
vivid
ignored
wily
Fixed 8u66-b17-1
released
References