MEDIUM · 4.3

CVE-2011-3389

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode wit...

Vulnerability Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GoogleChrome-
MicrosoftInternet Explorer-
MozillaFirefox-
OperaOpera Browser-
MicrosoftWindows-
SiemensSimatic Rf68Xr Firmware< 3.2.1
SiemensSimatic Rf68Xr-
SiemensSimatic Rf615R Firmware< 3.2.1
SiemensSimatic Rf615R-
HaxxCurl>= 7.10.6, <= 7.23.1
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus6.2
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Workstation5.0
DebianDebian Linux5.0
CanonicalUbuntu Linux10.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-3389?

CVE-2011-3389 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode wit...

How severe is CVE-2011-3389?

CVE-2011-3389 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-3389?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Microsoft Internet Explorer, Mozilla Firefox, Opera Opera Browser, Microsoft Windows.