CVE-2011-3389
curl - several
EPSS 73.3%
描述
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
如何修補 CVE-2011-3389
要修補 CVE-2011-3389,請將受影響套件升級到下列已修補版本。
- —升級至 1:13.7.2~dfsg-1 或更新版本
- —升級至 1.49+dfsg-1 或更新版本
- —升級至 7.24.0-1 或更新版本
- —升級至 1:15.b-dfsg-1 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.4.30-1 或更新版本
- —升級至 3.13.1.with.ckbi.1.88-1 或更新版本
- —升級至 2.6-2 或更新版本
- —升級至 2.7.3~rc1-1 或更新版本
CVE-2011-3389 正在被利用嗎?
可能 — EPSS 為 73.3%,屬於高被利用機率區間,建議優先修補。
受影響套件(10)
- from 0, < 1:13.7.2~dfsg-1
- from 0, < 1.49+dfsg-1
- from 0, < 7.24.0-1
- from 0, < 1:15.b-dfsg-1
- from 0
- from 0
- from 0, < 1.4.30-1
- from 0, < 3.13.1.with.ckbi.1.88-1
- from 0, < 2.6-2
- from 0, < 2.7.3~rc1-1