Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 15 min 113 bronnen 1 kritiek 12 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2014-3566

LOW · 3.4 CVSS Gepubliceerd: CWE-310

Beschrijving

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Vendors

Redhat Ibm Apple Mageia Novell Opensuse Fedoraproject Openssl Netbsd Debian Oracle

Affected products

Enterprise Linux Enterprise Linux Desktop Enterprise Linux Desktop Supplementary Enterprise Linux Server Enterprise Linux Server Supplementary Enterprise Linux Workstation Enterprise Linux Workstation Supplementary Aix Mac Os X Mageia Suse Linux Enterprise Desktop Suse Linux Enterprise Software Development Kit Suse Linux Enterprise Server Opensuse Fedora Openssl Vios Netbsd Debian Linux Database

References