CVE-2015-4000
21.05.2015, 00:59
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 1.0.1 ≤ 𝑥 ≤ 1.0.1m |
openssl | openssl | 1.0.2 ≤ 𝑥 ≤ 1.0.2a |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 14.10 |
canonical | ubuntu_linux | 15.04 |
openssl | openssl | 𝑥 ≤ 1.0.1m |
ibm | content_manager | 8.5 |
oracle | jrockit | r28.3.6 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
oracle | jdk | 1.6.0 |
oracle | jdk | 1.7.0 |
oracle | jdk | 1.7.0 |
oracle | jdk | 1.8.0 |
oracle | jdk | 1.8.0 |
oracle | jre | 1.6.0 |
oracle | jre | 1.7.0 |
oracle | jre | 1.7.0 |
oracle | jre | 1.8.0 |
oracle | jre | 1.8.0 |
suse | linux_enterprise_server | 11.0:sp4 |
apple | iphone_os | 𝑥 ≤ 8.3 |
apple | mac_os_x | 𝑥 ≤ 10.10.3 |
mozilla | network_security_services | 3.19 |
oracle | sparc-opl_service_processor | 𝑥 ≤ 1121 |
apple | safari | - |
chrome | - | |
microsoft | internet_explorer | - |
mozilla | firefox | - |
opera | opera_browser | - |
mozilla | firefox | 38.1.0 |
mozilla | firefox | 39.0 |
mozilla | firefox_esr | 31.8 |
mozilla | seamonkey | 2.35 |
mozilla | thunderbird | 31.8 |
mozilla | thunderbird | 38.1 |
mozilla | firefox_os | 2.2 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
nss |
| ||||||||||||||
openjdk-8 |
| ||||||||||||||
openssl |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
apache2 |
| ||||||||||||||||||||||||
firefox |
| ||||||||||||||||||||||||
gnutls26 |
| ||||||||||||||||||||||||
gnutls28 |
| ||||||||||||||||||||||||
nss |
| ||||||||||||||||||||||||
openjdk-6 |
| ||||||||||||||||||||||||
openjdk-7 |
| ||||||||||||||||||||||||
openjdk-8 |
| ||||||||||||||||||||||||
openssl |
| ||||||||||||||||||||||||
openssl098 |
| ||||||||||||||||||||||||
thunderbird |
|
Common Weakness Enumeration
References