Lucene search

K
securityvulnsFULL-DISCLOSURESECURITYVULNS:VULN:5321
HistoryOct 11, 2005 - 12:00 a.m.

OpenSSL SSL 2.0 rollback (weak cryptography)

2005-10-1100:00:00
FULL-DISCLOSURE
vulners.com
29

Active man-in-the-middle attacker can force rollback to SSL 2.0 protocol with known cryptographic weakness for both client and server if SSL_OP_MSIE_SSLV2_RSA_PADDING (or SSL_OP_ALL) configuration option is enabled.

CPENameOperatorVersion
openssleq0.9