Vulnerability Description
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 0.9.7 |
References
- ftp://ftp.software.ibm.com/pc/pccbbs/pc_servers/dir5.10.3_docs_relnotes.pdf
- http://docs.info.apple.com/article.html?artnum=302847
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html
- http://secunia.com/advisories/17146
- http://secunia.com/advisories/17151
- http://secunia.com/advisories/17153
- http://secunia.com/advisories/17169
- http://secunia.com/advisories/17178
- http://secunia.com/advisories/17180
- http://secunia.com/advisories/17189
- http://secunia.com/advisories/17191
- http://secunia.com/advisories/17210
- http://secunia.com/advisories/17259
FAQ
What is CVE-2005-2969?
CVE-2005-2969 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for prevent...
How severe is CVE-2005-2969?
CVE-2005-2969 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2969?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl.