多个厂商TLS协议和SSL协议会话协商明文注入漏洞

admin 2022-07-23 16:21:58 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

多个厂商TLS协议和SSL协议会话协商明文注入漏洞

  • CNNVD编号:CNNVD-200911-069
  • 危害等级: 高危
  • CVE编号: CVE-2009-3555
  • 漏洞类型: 加密问题
  • 发布时间: 2009-11-09
  • 威胁类型: 远程
  • 更新时间: 2022-06-13
  • 厂        商: openssl
  • 漏洞来源: Mitsubishi Electri...

漏洞简介

传输层安全协议(TLS)是确保互联网上通信应用和其用户隐私的协议。

Apache HTTP Server 2.2.14及之前版本,OpenSSL 0.9.8l之前版本,GnuTLS 2.8.5及之前版本,Mozilla Network Security Services (NSS) 3.12.4及之前版本,多个Cisco产品,以及其他产品的TLS协议和SSL协议中存在会话协商明文注入漏洞。由于TLS协议和SSL协议实现模块没有适当将会话协商与现存连接关联,中间人攻击者可以通过发送一个未认证的请求,将数据注入到受TLS和SSL协议保护的HTTP会话和其它类型会话中。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

http://cvs.openssl.org/chngview?cn=18790

http://www.gnu.org/software/gnutls/download.HTML

http://httpd.apache.org/download.cgi

参考网址

来源:HP

链接:http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3521

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0807.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/39136

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0768.HTML

来源:BID

链接:https://www.securityfocus.com/bid/36935

来源:SECUNIA

链接:http://secunia.com/advisories/37504

来源:CONFIRM

链接:http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.HTML

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA10-287A.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0916

来源:SECUNIA

链接:http://secunia.com/advisories/37501

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0339.HTML

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/507952/100/0/threaded

来源:OPENBSD

链接:http://openbsd.org/errata45.HTML#010_openssl

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023224

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.HTML

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535

来源:MISC

链接:http://extendedsubset.com/?p=8

来源:CONFIRM

链接:http://www.openssl.org/news/secadv_20091111.txt

来源:CONFIRM

链接:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.HTML

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.HTML

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/516397/100/0/threaded

来源:SECUNIA

链接:http://secunia.com/advisories/39127

来源:SECUNIA

链接:http://secunia.com/advisories/39242

来源:SECUNIA

链接:http://secunia.com/advisories/39243

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/3069

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0987.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/37859

来源:DEBIAN

链接:https://www.debian.org/security/2009/dsa-1934

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.HTML

来源:UBUNTU

链接:http://ubuntu.com/usn/usn-923-1

来源:SECUNIA

链接:http://secunia.com/advisories/44183

来源:MLIST

链接:https://lists.apache.org/thread.HTML/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d@%3Cdev.tomcat.apache.org%3E

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2011/0086

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1350

来源:SECTRACK

链接:http://securitytracker.com/id?1023148

来源:SECUNIA

链接:http://secunia.com/advisories/39278

来源:GENTOO

链接:http://security.gentoo.org/glsa/glsa-200912-01.xml

来源:DEBIAN

链接:https://www.debian.org/security/2011/dsa-2141

来源:CONFIRM

链接:http://www.arubanetworks.com/support/alerts/aid-020810.txt

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0933

来源:AIXAPAR

链接:http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only

来源:MANDRIVA

链接:http://www.mandriva.com/security/advisories?name=MDVSA-2010:076

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023204

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023205

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023206

来源:CERT-VN

链接:http://www.kb.cert.org/vuls/id/120541

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023207

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023208

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2011-0880.HTML

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023209

来源:MISC

链接:http://clicky.me/tlsvuln

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023210

来源:SECUNIA

链接:http://secunia.com/advisories/44954

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023211

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023212

来源:SECUNIA

链接:http://secunia.com/advisories/37640

来源:CONFIRM

链接:http://www-01.ibm.com/support/docview.wss?uid=swg24006386

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1107

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/3086

来源:MISC

链接:http://extendedsubset.com/Renegotiating_TLS.pdf

来源:CONFIRM

链接:http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.HTML

来源:CONFIRM

链接:https://www.vmware.com/security/advisories/VMSA-2011-0003.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/38056

来源:CONFIRM

链接:http://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT4004

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.HTML

来源:HP

链接:http://marc.info/?l=bugtraq&m=130497311408250&w=2

来源:MANDRIVA

链接:http://www.mandriva.com/security/advisories?name=MDVSA-2010:084

来源:MISC

链接:http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.HTML

来源:MANDRIVA

链接:http://www.mandriva.com/security/advisories?name=MDVSA-2010:089

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023213

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023214

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023215

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023216

来源:SECTRACK

链接:http://www.securitytracker.com/id?1024789

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/39819

来源:CONFIRM

链接:http://support.avaya.com/CSS/P8/documents/100114327

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023217

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023218

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023219

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0337.HTML

来源:MISC

链接:https://bugzilla.mozilla.org/show_bug.cgi?id=526689

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3164

来源:CONFIRM

链接:http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3165

来源:SECUNIA

链接:http://secunia.com/advisories/38003

来源:MLIST

链接:http://www.ietf.org/mail-archive/web/tls/current/msg03928.HTML

来源:CONFIRM

链接:http://www.mozilla.org/security/announce/2010/mfsa2010-22.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/37399

来源:SECUNIA

链接:http://secunia.com/advisories/38241

来源:CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple

链接:http://lists.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/archives/security-announce/2010//May/msg00001.HTML

来源:UBUNTU

链接:http://www.ubuntu.com/usn/USN-1010-1

来源:SECUNIA

链接:http://secunia.com/advisories/38484

来源:CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple

链接:http://lists.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/archives/security-announce/2010//May/msg00002.HTML

来源:MISC

链接:http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.HTML

来源:HP

链接:http://marc.info/?l=bugtraq&m=142660345230545&w=2

来源:HP

链接:http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023426

来源:CISCO

链接:http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.sHTML

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023427

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.HTML

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023428

来源:CONFIRM

链接:http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/508075/100/0/threaded

来源:MISC

链接:http://blogs.iss.net/archive/sslmitmiscsrf.HTML

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0165.HTML

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.HTML

来源:HP

链接:http://marc.info/?l=bugtraq&m=127557596201693&w=2

来源:SECUNIA

链接:http://secunia.com/advisories/37383

来源:CONFIRM

链接:http://www.opera.com/support/search/view/944/

来源:MS

链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0130.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/40545

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/39317

来源:CONFIRM

链接:http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.HTML

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578

来源:SECUNIA

链接:http://secunia.com/advisories/37291

来源:UBUNTU

链接:http://www.ubuntu.com/usn/USN-927-4

来源:OPENBSD

链接:http://openbsd.org/errata46.HTML#004_openssl

来源:SECUNIA

链接:http://secunia.com/advisories/37292

来源:MISC

链接:http://www.betanews.com/article/1257452450

来源:UBUNTU

链接:http://www.ubuntu.com/usn/USN-927-5

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.HTML

来源:CONFIRM

链接:http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.HTML

来源:MLIST

链接:https://lists.apache.org/thread.HTML/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E

来源:MLIST

链接:http://marc.info/?l=cryptography&m=125752275331877&w=2

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1

来源:UBUNTU

链接:http://www.ubuntu.com/usn/USN-927-1

来源:CONFIRM

链接:https://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/42724

来源:DEBIAN

链接:http://www.debian.org/security/2009/dsa-1934

来源:SECUNIA

链接:http://secunia.com/advisories/38020

来源:CONFIRM

链接:http://www.openoffice.org/security/cves/CVE-2009-3555.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0982

来源:OSVDB

链接:http://osvdb.org/65202

来源:SECUNIA

链接:http://secunia.com/advisories/37604

来源:CONFIRM

链接:http://support.avaya.com/CSS/P8/documents/100070150

来源:HP

链接:http://www.securityfocus.com/archive/1/522176

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2011/0033

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2011/0032

来源:CONFIRM

链接:http://www-01.ibm.com/support/docview.wss?uid=swg21432298

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0173

来源:CONFIRM

链接:http://wiki.rpath.com/Advisories:rPSA-2009-0155

来源:MISC

链接:http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-Javascript-injection-example-poc-report.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/42733

来源:CONFIRM

链接:http://support.avaya.com/CSS/P8/documents/100081611

来源:CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple

链接:http://lists.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/archives/security-announce/2010/Jan/msg00000.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/39461

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1

来源:BID

链接:http://www.securityfocus.com/bid/36935

来源:HP

链接:http://marc.info/?l=bugtraq&m=134254866602253&w=2

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0848

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023411

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0086

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1054

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/07/3

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0338.HTML

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0155.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/41972

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3484

来源:OSVDB

链接:http://osvdb.org/60521

来源:SECUNIA

链接:http://secunia.com/advisories/38687

来源:CONFIRM

链接:https://kb.bluecoat.com/index?page=content&id=SA50

来源:CONFIRM

链接:http://sysoev.ru/nginx/patch.cve-2009-3555.txt

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0770.HTML

来源:DEBIAN

链接:http://www.debian.org/security/2011/dsa-2141

来源:MLIST

链接:http://lists.gnu.org/archive/HTML/gnutls-devel/2009-11/msg00029.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3354

来源:SECUNIA

链接:http://secunia.com/advisories/40070

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/2010

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3353

来源:HP

链接:http://marc.info/?l=bugtraq&m=127419602507642&w=2

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0994

来源:SECUNIA

链接:http://secunia.com/advisories/40747

来源:SECUNIA

链接:http://secunia.com/advisories/40866

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0748

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.HTML

来源:HP

链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041

来源:CONFIRM

链接:http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.HTML

来源:MLIST

链接:https://lists.apache.org/thread.HTML/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2@%3Cdev.tomcat.apache.org%3E

来源:MLIST

链接:http://www.ietf.org/mail-archive/web/tls/current/msg03948.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.HTML

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/06/3

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023163

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0119.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.HTML

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.HTML

来源:MISC

链接:https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/42808

来源:CONFIRM

链接:http://www.opera.com/docs/changelogs/unix/1060/

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1191

来源:AIXAPAR

链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848

来源:MISC

链接:https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/3126

来源:FULLDISC

链接:http://seclists.org/fulldisclosure/2009/Nov/139

来源:SECUNIA

链接:http://secunia.com/advisories/42377

来源:SECUNIA

链接:http://secunia.com/advisories/42379

来源:HP

链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686

来源:SECUNIA

链接:http://secunia.com/advisories/42811

来源:GENTOO

链接:http://security.gentoo.org/glsa/glsa-201406-32.xml

来源:SECUNIA

链接:http://secunia.com/advisories/41967

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0986.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/42816

来源:MLIST

链接:https://lists.apache.org/thread.HTML/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220@%3Cdev.tomcat.apache.org%3E

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0167.HTML

来源:AIXAPAR

链接:http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247

来源:CONFIRM

链接:http://www.ingate.com/Relnote.php?ver=481

来源:DEBIAN

链接:https://www.debian.org/security/2015/dsa-3253

来源:SECUNIA

链接:http://secunia.com/advisories/39292

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/05/3

来源:SECUNIA

链接:http://secunia.com/advisories/41490

来源:DEBIAN

链接:http://www.debian.org/security/2015/dsa-3253

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/05/5

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/2745

来源:SECUNIA

链接:http://secunia.com/advisories/42467

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1

来源:CONFIRM

链接:http://www-01.ibm.com/support/docview.wss?uid=swg24025312

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.HTML

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.HTML

来源:httpd-announce&m=125755783724966&w=2

链接:httpd-announce&m=125755783724966&w=2

来源:MLIST

链接:http://marc.info/?l=apache-

来源:SECUNIA

链接:http://secunia.com/advisories/37675

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/20/1

来源:SLACKWARE

链接:http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446

来源:SECUNIA

链接:http://secunia.com/advisories/41818

来源:FEDORA

链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.HTML

来源:MISC

链接:http://www.tombom.co.uk/blog/?p=85

来源:FEDORA

链接:http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3205

来源:CONFIRM

链接:http://support.avaya.com/CSS/P8/documents/100114315

来源:CONFIRM

链接:http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.HTML

来源:CONFIRM

链接:http://www.vmware.com/security/advisories/VMSA-2011-0003.HTML

来源:CONFIRM

链接:http://support.citrix.com/article/CTX123359

来源:MLIST

链接:http://www.openwall.com/lists/oss-security/2009/11/23/10

来源:HP

链接:http://marc.info/?l=bugtraq&m=132077688910227&w=2

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023271

来源:SECUNIA

链接:http://secunia.com/advisories/41480

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023272

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3310

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023273

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3313

来源:SECUNIA

链接:http://secunia.com/advisories/48577

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023274

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023275

来源:GENTOO

链接:http://security.gentoo.org/glsa/glsa-201203-22.xml

来源:AIXAPAR

链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/515055/100/0/threaded

来源:AIXAPAR

链接:http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023270

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1639

来源:SECUNIA

链接:http://secunia.com/advisories/37656

来源:XF

链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/54158

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617

来源:SECUNIA

链接:http://secunia.com/advisories/39713

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088

来源:CONFIRM

链接:https://bugzilla.mozilla.org/show_bug.cgi?id=545755

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1793

来源:HP

链接:http://marc.info/?l=bugtraq&m=127128920008563&w=2

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3587

来源:CONFIRM

链接:http://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT4170

来源:CONFIRM

链接:http://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT4171

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023243

来源:BUGTRAQ

链接:http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.HTML

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2009/3220

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0865.HTML

来源:SECUNIA

链接:http://secunia.com/advisories/37453

来源:SECUNIA

链接:http://secunia.com/advisories/39632

来源:SECUNIA

链接:http://secunia.com/advisories/38781

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1673

来源:SECUNIA

链接:http://secunia.com/advisories/39628

来源:OSVDB

链接:http://osvdb.org/62210

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/508130/100/0/threaded

来源:CONFIRM

链接:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA10-222A.HTML

来源:CONFIRM

链接:https://bugzilla.redhat.com/show_bug.cgi?id=533125

来源:CONFIRM

链接:https://support.citrix.com/article/CTX123359

来源:CONFIRM

链接:https://www.vmware.com/security/advisories/VMSA-2010-0019.HTML

来源:MISC

链接:http://www.links.org/?p=780

来源:MISC

链接:http://www.links.org/?p=786

来源:CONFIRM

链接:http://www-01.ibm.com/support/docview.wss?uid=swg21426108

来源:CONFIRM

链接:http://www.vmware.com/security/advisories/VMSA-2010-0019.HTML

来源:HP

链接:http://marc.info/?l=bugtraq&m=126150535619567&w=2

来源:SECUNIA

链接:http://secunia.com/advisories/37320

来源:OSVDB

链接:http://osvdb.org/60972

来源:MISC

链接:http://www.links.org/?p=789

来源:SECUNIA

链接:http://secunia.com/advisories/39500

来源:SECUNIA

链接:http://secunia.com/advisories/43308

来源:CONFIRM

链接:http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2010-0786.HTML

来源:MISC

链接:http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.HTML

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366

来源:CONFIRM

链接:http://kbase.redhat.com/faq/docs/DOC-20491

来源:HP

链接:http://marc.info/?l=bugtraq&m=133469267822771&w=2

来源:kb.juniper.net

链接:http://kb.juniper.net/InfoCenter/index?page=content&id=jsA10939

来源:us-cert.cisa.gov

链接:https://us-cert.cisa.gov/ics/advisories/icsa-22-160-01

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-have-been-identified-in-ibm-tivoli-netcool-omnibus-probe-for-network-node-manager-i-cve-2009-3555/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2561/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2022.2853

受影响实体

  • Openssl Openssl:0.9.6c  
  • Openssl Openssl:0.9.6h  
  • Openssl Openssl:0.9.6i  
  • Openssl Openssl:0.9.6f  
  • Openssl Openssl:0.9.6g  

补丁

  • Security Update for Windows Server 2008 for Itanium-based Systems (KB980436)
  • Security Update for Windows Server 2008 R2 x64 Edition (KB980436)
  • Security Update for Windows Server 2003 x64 Edition (KB980436)
  • Security Update for Windows Server 2008 (KB980436)
  • Security Update for Windows 7 for x64-based Systems (KB980436)

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0