Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-1968 – The Raccoon attack exploits a flaw in the TLS specification which can lea

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1968

Reference (s):

  • https://security.netapp.com/advisory/ntap-20200911-0004/
  • URL: https://security.netapp.com/advisory/ntap-20200911-0004/
  • https://www.openssl.org/news/secadv/20200909.txt
  • URL: https://www.openssl.org/news/secadv/20200909.txt
  • https://www.oracle.com//security-alerts/cpujul2021.html
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser