Name | CVE-2016-0800 |
Description | The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
NVD severity | medium |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
nss (PTS) | stretch | 2:3.26.2-1.1+deb9u1 | fixed |
stretch (security) | 2:3.26.2-1.1+deb9u2 | fixed | |
buster, buster (security) | 2:3.42.1-1+deb10u3 | fixed | |
bullseye | 2:3.61-1 | fixed | |
sid | 2:3.63-1 | fixed | |
openssl (PTS) | stretch | 1.1.0l-1~deb9u1 | fixed |
stretch (security) | 1.1.0l-1~deb9u3 | fixed | |
buster | 1.1.1d-0+deb10u5 | fixed | |
buster (security) | 1.1.1d-0+deb10u6 | fixed | |
bullseye, sid | 1.1.1k-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
nss | source | (unstable) | 3.13 | |||
openssl | source | (unstable) | 1.0.0c-2 |
openssl 1.0.0c-2 dropped SSLv2 support
NSS disabled SSLv2 by default in 3.13
https://www.openssl.org/news/secadv/20160301.txt
https://www.drownattack.com/
GNUTLS never implemented SSLv2
http://blog.cryptographyengineering.com/2016/03/attack-of-week-drown.html