CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
opensslopenssl
1.0.1 ≤
𝑥
≤ 1.0.1m
opensslopenssl
1.0.2 ≤
𝑥
≤ 1.0.2a
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
opensslopenssl
𝑥
≤ 1.0.1m
ibmcontent_manager
8.5
oraclejrockit
r28.3.6
debiandebian_linux
7.0
debiandebian_linux
8.0
oraclejdk
1.6.0
oraclejdk
1.7.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejdk
1.8.0
oraclejre
1.6.0
oraclejre
1.7.0
oraclejre
1.7.0
oraclejre
1.8.0
oraclejre
1.8.0
suselinux_enterprise_server
11.0:sp4
appleiphone_os
𝑥
≤ 8.3
applemac_os_x
𝑥
≤ 10.10.3
mozillanetwork_security_services
3.19
oraclesparc-opl_service_processor
𝑥
≤ 1121
applesafari
-
googlechrome
-
microsoftinternet_explorer
-
mozillafirefox
-
operaopera_browser
-
mozillafirefox
38.1.0
mozillafirefox
39.0
mozillafirefox_esr
31.8
mozillaseamonkey
2.35
mozillathunderbird
31.8
mozillathunderbird
38.1
mozillafirefox_os
2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
squeeze
no-dsa
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
openjdk-8
sid
8u432-b06-2
fixed
squeeze
no-dsa
openssl
bullseye
1.1.1w-0+deb11u1
fixed
squeeze
no-dsa
bullseye (security)
1.1.1w-0+deb11u2
fixed
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
sid
3.3.2-2
fixed
trixie
3.3.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
precise
Fixed 2.2.22-1ubuntu1.9
released
firefox
disco
Fixed 39.0+build5-0ubuntu1
released
cosmic
Fixed 39.0+build5-0ubuntu1
released
bionic
Fixed 39.0+build5-0ubuntu1
released
artful
Fixed 39.0+build5-0ubuntu1
released
zesty
Fixed 39.0+build5-0ubuntu1
released
yakkety
Fixed 39.0+build5-0ubuntu1
released
xenial
Fixed 39.0+build5-0ubuntu1
released
wily
Fixed 39.0+build5-0ubuntu1
released
vivid
Fixed 39.0+build5-0ubuntu0.15.04.1
released
utopic
Fixed 39.0+build5-0ubuntu0.14.10.1
released
trusty
Fixed 39.0+build5-0ubuntu0.14.04.1
released
precise
Fixed 39.0+build5-0ubuntu0.12.04.2
released
gnutls26
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
not-affected
trusty
not-affected
precise
not-affected
gnutls28
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
precise
not-affected
nss
disco
Fixed 2:3.19.2-1ubuntu1
released
cosmic
Fixed 2:3.19.2-1ubuntu1
released
bionic
Fixed 2:3.19.2-1ubuntu1
released
artful
Fixed 2:3.19.2-1ubuntu1
released
zesty
Fixed 2:3.19.2-1ubuntu1
released
yakkety
Fixed 2:3.19.2-1ubuntu1
released
xenial
Fixed 2:3.19.2-1ubuntu1
released
wily
Fixed 2:3.19.2-1ubuntu1
released
vivid
Fixed 2:3.19.2-0ubuntu15.04.1
released
utopic
Fixed 2:3.19.2-0ubuntu0.14.10.1
released
trusty
Fixed 2:3.19.2-0ubuntu0.14.04.1
released
precise
Fixed 3.19.2-0ubuntu0.12.04.1
released
openjdk-6
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
Fixed 6b36-1.13.8-0ubuntu1~15.04.1
released
utopic
ignored
trusty
Fixed 6b36-1.13.8-0ubuntu1~14.04
released
precise
Fixed 6b36-1.13.8-0ubuntu1~12.04
released
openjdk-7
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
Fixed 7u79-2.5.6-0ubuntu1.15.04.1
released
utopic
ignored
trusty
Fixed 7u79-2.5.6-0ubuntu1.14.04.1
released
precise
Fixed 7u79-2.5.6-0ubuntu1.12.04.1
released
openjdk-8
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
Fixed 8u66-b17-1
released
vivid
ignored
utopic
ignored
trusty
dne
precise
dne
openssl
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
Fixed 1.0.1f-1ubuntu11.1
released
utopic
Fixed 1.0.1f-1ubuntu9.5
released
trusty
Fixed 1.0.1f-1ubuntu2.12
released
precise
Fixed 1.0.1-4ubuntu5.28
released
openssl098
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
ignored
utopic
ignored
trusty
dne
precise
ignored
thunderbird
disco
Fixed 1:31.8.0+build1-0ubuntu1
released
cosmic
Fixed 1:31.8.0+build1-0ubuntu1
released
bionic
Fixed 1:31.8.0+build1-0ubuntu1
released
artful
Fixed 1:31.8.0+build1-0ubuntu1
released
zesty
Fixed 1:31.8.0+build1-0ubuntu1
released
yakkety
Fixed 1:31.8.0+build1-0ubuntu1
released
xenial
Fixed 1:31.8.0+build1-0ubuntu1
released
wily
Fixed 1:31.8.0+build1-0ubuntu1
released
vivid
Fixed 1:31.8.0+build1-0ubuntu0.15.04.1
released
utopic
Fixed 1:31.8.0+build1-0ubuntu0.14.10.1
released
trusty
Fixed 1:31.8.0+build1-0ubuntu0.14.04.1
released
precise
Fixed 1:31.8.0+build1-0ubuntu0.12.04.1
released
Common Weakness Enumeration
References