CVE-2011-3389

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
References
Link Resource
http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/ Third Party Advisory
http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx Third Party Advisory
http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx Third Party Advisory
http://curl.haxx.se/docs/adv_20120124B.html Third Party Advisory
http://downloads.asterisk.org/pub/security/AST-2016-001.html Third Party Advisory
http://ekoparty.org/2011/juliano-rizzo.php Broken Link
http://eprint.iacr.org/2004/111 Third Party Advisory
http://eprint.iacr.org/2006/136 Third Party Advisory
http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html Not Applicable Vendor Advisory
http://isc.sans.edu/diary/SSL+TLS+part+3+/11635 Third Party Advisory
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html Broken Link
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html Broken Link
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html Broken Link Mailing List
http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html Broken Link Mailing List
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html Broken Link Mailing List
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html Broken Link Mailing List
http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html Broken Link Mailing List
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html Broken Link
http://marc.info/?l=bugtraq&m=132750579901589&w=2 Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=132872385320240&w=2 Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133365109612558&w=2 Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133728004526190&w=2 Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=134254866602253&w=2 Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=134254957702612&w=2 Issue Tracking Mailing List Third Party Advisory
http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue Third Party Advisory
http://osvdb.org/74829 Broken Link
http://rhn.redhat.com/errata/RHSA-2012-0508.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html Broken Link
http://secunia.com/advisories/45791 Not Applicable
http://secunia.com/advisories/47998 Not Applicable
http://secunia.com/advisories/48256 Not Applicable
http://secunia.com/advisories/48692 Not Applicable
http://secunia.com/advisories/48915 Not Applicable
http://secunia.com/advisories/48948 Not Applicable
http://secunia.com/advisories/49198 Not Applicable
http://secunia.com/advisories/55322 Not Applicable
http://secunia.com/advisories/55350 Not Applicable
http://secunia.com/advisories/55351 Not Applicable
http://security.gentoo.org/glsa/glsa-201203-02.xml Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://support.apple.com/kb/HT4999 Third Party Advisory
http://support.apple.com/kb/HT5001 Third Party Advisory
http://support.apple.com/kb/HT5130 Third Party Advisory
http://support.apple.com/kb/HT5281 Broken Link
http://support.apple.com/kb/HT5501 Third Party Advisory
http://support.apple.com/kb/HT6150 Third Party Advisory
http://technet.microsoft.com/security/advisory/2588513 Patch Vendor Advisory
http://vnhacker.blogspot.com/2011/09/beast.html Third Party Advisory
http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf Third Party Advisory
http://www.debian.org/security/2012/dsa-2398 Third Party Advisory
http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html Broken Link
http://www.ibm.com/developerworks/java/jdk/alerts/ Third Party Advisory
http://www.imperialviolet.org/2011/09/23/chromeandbeast.html Third Party Advisory
http://www.insecure.cl/Beast-SSL.rar Broken Link Patch
http://www.kb.cert.org/vuls/id/864643 Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2012:058 Broken Link
http://www.opera.com/docs/changelogs/mac/1151/ Third Party Advisory
http://www.opera.com/docs/changelogs/mac/1160/ Third Party Advisory
http://www.opera.com/docs/changelogs/unix/1151/ Third Party Advisory
http://www.opera.com/docs/changelogs/unix/1160/ Third Party Advisory
http://www.opera.com/docs/changelogs/windows/1151/ Third Party Advisory
http://www.opera.com/docs/changelogs/windows/1160/ Third Party Advisory
http://www.opera.com/support/kb/view/1004/ Third Party Advisory Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1384.html Third Party Advisory Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2012-0006.html Third Party Advisory
http://www.securityfocus.com/bid/49388 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/49778 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029190 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1025997 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1026103 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1026704 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1263-1 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA12-010A.html Third Party Advisory US Government Resource
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail Third Party Advisory
https://bugzilla.novell.com/show_bug.cgi?id=719047 Issue Tracking Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=737506 Issue Tracking Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006 Patch Vendor Advisory
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 Broken Link
https://hermes.opensuse.org/messages/13154861 Broken Link
https://hermes.opensuse.org/messages/13155432 Broken Link
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party Advisory US Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_rf68xr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rf68xr:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_rf615r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rf615r:-:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*

History

29 Nov 2022, 15:56

Type Values Removed Values Added
References (MISC) http://isc.sans.edu/diary/SSL+TLS+part+3+/11635 - (MISC) http://isc.sans.edu/diary/SSL+TLS+part+3+/11635 - Third Party Advisory
References (CONFIRM) http://downloads.asterisk.org/pub/security/AST-2016-001.html - (CONFIRM) http://downloads.asterisk.org/pub/security/AST-2016-001.html - Third Party Advisory
References (APPLE) http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html - (APPLE) http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html - Broken Link, Mailing List
References (CONFIRM) http://support.apple.com/kb/HT4999 - (CONFIRM) http://support.apple.com/kb/HT4999 - Third Party Advisory
References (CONFIRM) http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html - (CONFIRM) http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/55322 - (SECUNIA) http://secunia.com/advisories/55322 - Not Applicable
References (MISC) http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html - (MISC) http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html - Broken Link
References (MISC) http://eprint.iacr.org/2006/136 - (MISC) http://eprint.iacr.org/2006/136 - Third Party Advisory
References (APPLE) http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html - (APPLE) http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html - Broken Link
References (CONFIRM) http://www.opera.com/docs/changelogs/windows/1151/ - (CONFIRM) http://www.opera.com/docs/changelogs/windows/1151/ - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html - Broken Link
References (SECUNIA) http://secunia.com/advisories/49198 - (SECUNIA) http://secunia.com/advisories/49198 - Not Applicable
References (MISC) http://www.insecure.cl/Beast-SSL.rar - Patch (MISC) http://www.insecure.cl/Beast-SSL.rar - Broken Link, Patch
References (UBUNTU) http://www.ubuntu.com/usn/USN-1263-1 - (UBUNTU) http://www.ubuntu.com/usn/USN-1263-1 - Third Party Advisory
References (APPLE) http://lists.apple.com/archives/security-announce/2012/May/msg00001.html - (APPLE) http://lists.apple.com/archives/security-announce/2012/May/msg00001.html - Broken Link, Mailing List
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html - Broken Link
References (APPLE) http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html - (APPLE) http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html - Broken Link
References (GENTOO) http://security.gentoo.org/glsa/glsa-201406-32.xml - (GENTOO) http://security.gentoo.org/glsa/glsa-201406-32.xml - Third Party Advisory
References (CONFIRM) http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/ - (CONFIRM) http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/ - Third Party Advisory
References (HP) http://marc.info/?l=bugtraq&m=133365109612558&w=2 - (HP) http://marc.info/?l=bugtraq&m=133365109612558&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (SUSE) https://hermes.opensuse.org/messages/13154861 - (SUSE) https://hermes.opensuse.org/messages/13154861 - Broken Link
References (APPLE) http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html - (APPLE) http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html - Broken Link, Mailing List
References (MISC) http://vnhacker.blogspot.com/2011/09/beast.html - (MISC) http://vnhacker.blogspot.com/2011/09/beast.html - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html - Broken Link
References (SECTRACK) http://www.securitytracker.com/id?1025997 - (SECTRACK) http://www.securitytracker.com/id?1025997 - Broken Link, Third Party Advisory, VDB Entry
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2012-0006.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2012-0006.html - Third Party Advisory
References (CONFIRM) http://www.opera.com/docs/changelogs/mac/1151/ - (CONFIRM) http://www.opera.com/docs/changelogs/mac/1151/ - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/49388 - (BID) http://www.securityfocus.com/bid/49388 - Third Party Advisory, VDB Entry
References (SECTRACK) http://www.securitytracker.com/id?1026103 - (SECTRACK) http://www.securitytracker.com/id?1026103 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) http://www.imperialviolet.org/2011/09/23/chromeandbeast.html - (CONFIRM) http://www.imperialviolet.org/2011/09/23/chromeandbeast.html - Third Party Advisory
References (HP) http://marc.info/?l=bugtraq&m=132750579901589&w=2 - (HP) http://marc.info/?l=bugtraq&m=132750579901589&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (CONFIRM) http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue - (CONFIRM) http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue - Third Party Advisory
References (CERT-VN) http://www.kb.cert.org/vuls/id/864643 - US Government Resource (CERT-VN) http://www.kb.cert.org/vuls/id/864643 - Third Party Advisory, US Government Resource
References (CONFIRM) http://www.opera.com/docs/changelogs/windows/1160/ - (CONFIRM) http://www.opera.com/docs/changelogs/windows/1160/ - Third Party Advisory
References (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2012:058 - (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2012:058 - Broken Link
References (SECTRACK) http://www.securitytracker.com/id?1026704 - (SECTRACK) http://www.securitytracker.com/id?1026704 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) http://support.apple.com/kb/HT5130 - (CONFIRM) http://support.apple.com/kb/HT5130 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/47998 - (SECUNIA) http://secunia.com/advisories/47998 - Not Applicable
References (CONFIRM) http://support.apple.com/kb/HT5501 - (CONFIRM) http://support.apple.com/kb/HT5501 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/48692 - (SECUNIA) http://secunia.com/advisories/48692 - Not Applicable
References (HP) https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 - (HP) https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 - Broken Link
References (HP) http://marc.info/?l=bugtraq&m=134254866602253&w=2 - (HP) http://marc.info/?l=bugtraq&m=134254866602253&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (CONFIRM) https://bugzilla.novell.com/show_bug.cgi?id=719047 - (CONFIRM) https://bugzilla.novell.com/show_bug.cgi?id=719047 - Issue Tracking, Third Party Advisory
References (CONFIRM) http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html - (CONFIRM) http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html - Third Party Advisory
References (MISC) https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 - (MISC) https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 - Third Party Advisory, US Government Resource
References (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006 - (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006 - Patch, Vendor Advisory
References (HP) http://marc.info/?l=bugtraq&m=132872385320240&w=2 - (HP) http://marc.info/?l=bugtraq&m=132872385320240&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (CONFIRM) http://support.apple.com/kb/HT5281 - (CONFIRM) http://support.apple.com/kb/HT5281 - Broken Link
References (CONFIRM) http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx - (CONFIRM) http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx - Third Party Advisory
References (CONFIRM) http://www.opera.com/docs/changelogs/unix/1160/ - (CONFIRM) http://www.opera.com/docs/changelogs/unix/1160/ - Third Party Advisory
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf - Third Party Advisory
References (CONFIRM) http://technet.microsoft.com/security/advisory/2588513 - (CONFIRM) http://technet.microsoft.com/security/advisory/2588513 - Patch, Vendor Advisory
References (CONFIRM) https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail - (CONFIRM) https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/48915 - (SECUNIA) http://secunia.com/advisories/48915 - Not Applicable
References (APPLE) http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html - (APPLE) http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html - Broken Link, Mailing List
References (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752 - (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752 - Third Party Advisory
References (CONFIRM) http://www.opera.com/support/kb/view/1004/ - Vendor Advisory (CONFIRM) http://www.opera.com/support/kb/view/1004/ - Third Party Advisory, Vendor Advisory
References (CONFIRM) http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf - (CONFIRM) http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf - Third Party Advisory
References (APPLE) http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html - (APPLE) http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html - Broken Link, Mailing List
References (BID) http://www.securityfocus.com/bid/49778 - (BID) http://www.securityfocus.com/bid/49778 - Third Party Advisory, VDB Entry
References (CONFIRM) http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx - (CONFIRM) http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx - Third Party Advisory
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2012-0508.html - (REDHAT) http://rhn.redhat.com/errata/RHSA-2012-0508.html - Third Party Advisory
References (DEBIAN) http://www.debian.org/security/2012/dsa-2398 - (DEBIAN) http://www.debian.org/security/2012/dsa-2398 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/48256 - (SECUNIA) http://secunia.com/advisories/48256 - Not Applicable
References (SECTRACK) http://www.securitytracker.com/id/1029190 - (SECTRACK) http://www.securitytracker.com/id/1029190 - Broken Link, Third Party Advisory, VDB Entry
References (CONFIRM) http://support.apple.com/kb/HT5001 - (CONFIRM) http://support.apple.com/kb/HT5001 - Third Party Advisory
References (CONFIRM) http://support.apple.com/kb/HT6150 - (CONFIRM) http://support.apple.com/kb/HT6150 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/55350 - (SECUNIA) http://secunia.com/advisories/55350 - Not Applicable
References (CONFIRM) http://www.opera.com/docs/changelogs/unix/1151/ - (CONFIRM) http://www.opera.com/docs/changelogs/unix/1151/ - Third Party Advisory
References (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=737506 - (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=737506 - Issue Tracking, Third Party Advisory
References (CONFIRM) http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html - (CONFIRM) http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/48948 - (SECUNIA) http://secunia.com/advisories/48948 - Not Applicable
References (HP) http://marc.info/?l=bugtraq&m=133728004526190&w=2 - (HP) http://marc.info/?l=bugtraq&m=133728004526190&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (CONFIRM) http://curl.haxx.se/docs/adv_20120124B.html - (CONFIRM) http://curl.haxx.se/docs/adv_20120124B.html - Third Party Advisory
References (SUSE) https://hermes.opensuse.org/messages/13155432 - (SUSE) https://hermes.opensuse.org/messages/13155432 - Broken Link
References (SECUNIA) http://secunia.com/advisories/45791 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/45791 - Not Applicable
References (CONFIRM) http://www.ibm.com/developerworks/java/jdk/alerts/ - (CONFIRM) http://www.ibm.com/developerworks/java/jdk/alerts/ - Third Party Advisory
References (OSVDB) http://osvdb.org/74829 - (OSVDB) http://osvdb.org/74829 - Broken Link
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2011-1384.html - Vendor Advisory (REDHAT) http://www.redhat.com/support/errata/RHSA-2011-1384.html - Third Party Advisory, Vendor Advisory
References (MISC) http://ekoparty.org/2011/juliano-rizzo.php - (MISC) http://ekoparty.org/2011/juliano-rizzo.php - Broken Link
References (SECUNIA) http://secunia.com/advisories/55351 - (SECUNIA) http://secunia.com/advisories/55351 - Not Applicable
References (MISC) http://eprint.iacr.org/2004/111 - (MISC) http://eprint.iacr.org/2004/111 - Third Party Advisory
References (CONFIRM) http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html - (CONFIRM) http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html - Not Applicable, Vendor Advisory
References (CONFIRM) http://www.opera.com/docs/changelogs/mac/1160/ - (CONFIRM) http://www.opera.com/docs/changelogs/mac/1160/ - Third Party Advisory
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2013-1455.html - (REDHAT) http://rhn.redhat.com/errata/RHSA-2013-1455.html - Broken Link
References (GENTOO) http://security.gentoo.org/glsa/glsa-201203-02.xml - (GENTOO) http://security.gentoo.org/glsa/glsa-201203-02.xml - Third Party Advisory
References (HP) http://marc.info/?l=bugtraq&m=134254957702612&w=2 - (HP) http://marc.info/?l=bugtraq&m=134254957702612&w=2 - Issue Tracking, Mailing List, Third Party Advisory
References (CERT) http://www.us-cert.gov/cas/techalerts/TA12-010A.html - US Government Resource (CERT) http://www.us-cert.gov/cas/techalerts/TA12-010A.html - Third Party Advisory, US Government Resource
CWE CWE-20 CWE-326
CPE cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rf615r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rf68xr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rf68xr:-:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_rf615r:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*

23 Jul 2021, 15:12

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:ie:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

Information

Published : 2011-09-06 19:55

Updated : 2024-02-04 17:54


NVD link : CVE-2011-3389

Mitre link : CVE-2011-3389

CVE.ORG link : CVE-2011-3389


JSON object : View

Products Affected

microsoft

  • windows
  • internet_explorer

debian

  • debian_linux

siemens

  • simatic_rf68xr
  • simatic_rf615r_firmware
  • simatic_rf68xr_firmware
  • simatic_rf615r

mozilla

  • firefox

canonical

  • ubuntu_linux

google

  • chrome

opera

  • opera_browser

redhat

  • enterprise_linux_desktop
  • enterprise_linux_server_aus
  • enterprise_linux_server
  • enterprise_linux_workstation
  • enterprise_linux_eus

haxx

  • curl
CWE
CWE-326

Inadequate Encryption Strength