CVE-2011-5095
EPSS 2.1%
描述
The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923.
如何修補 CVE-2011-5095
要修補 CVE-2011-5095,請將受影響套件升級到下列已修補版本。
- Debian/openssl—升級至 0.9.8a-1 或更新版本
CVE-2011-5095 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.9.8a-1