CVE-2015-4000
21.05.2015, 00:59
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openssl | openssl | 1.0.1 ≤ 𝑥 ≤ 1.0.1m |
| openssl | openssl | 1.0.2 ≤ 𝑥 ≤ 1.0.2a |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| canonical | ubuntu_linux | 15.04 |
| openssl | openssl | 𝑥 ≤ 1.0.1m |
| ibm | content_manager | 8.5 |
| oracle | jrockit | r28.3.6 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.7.0 |
| oracle | jdk | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jdk | 1.8.0 |
| oracle | jre | 1.6.0 |
| oracle | jre | 1.7.0 |
| oracle | jre | 1.7.0 |
| oracle | jre | 1.8.0 |
| oracle | jre | 1.8.0 |
| suse | linux_enterprise_server | 11.0:sp4 |
| apple | iphone_os | 𝑥 ≤ 8.3 |
| apple | mac_os_x | 𝑥 ≤ 10.10.3 |
| mozilla | network_security_services | 3.19 |
| oracle | sparc-opl_service_processor | 𝑥 ≤ 1121 |
| apple | safari | - |
| chrome | - | |
| microsoft | internet_explorer | - |
| mozilla | firefox | - |
| opera | opera_browser | - |
| mozilla | firefox | 38.1.0 |
| mozilla | firefox | 39.0 |
| mozilla | firefox_esr | 31.8 |
| mozilla | seamonkey | 2.35 |
| mozilla | thunderbird | 31.8 |
| mozilla | thunderbird | 38.1 |
| mozilla | firefox_os | 2.2 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| nss |
| ||||||||||||||
| openjdk-8 |
| ||||||||||||||
| openssl |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||||||||||
| firefox |
| ||||||||||||||||||||||||
| gnutls26 |
| ||||||||||||||||||||||||
| gnutls28 |
| ||||||||||||||||||||||||
| nss |
| ||||||||||||||||||||||||
| openjdk-6 |
| ||||||||||||||||||||||||
| openjdk-7 |
| ||||||||||||||||||||||||
| openjdk-8 |
| ||||||||||||||||||||||||
| openssl |
| ||||||||||||||||||||||||
| openssl098 |
| ||||||||||||||||||||||||
| thunderbird |
|
Common Weakness Enumeration
References