Name | CVE-2005-2969 |
Description | The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-875-1, DSA-881-1, DSA-882-1, DSA-888-1 |
Debian Bugs | 333500 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
openssl (PTS) | jessie, jessie (lts) | 1.0.1t-1+deb8u22 | fixed |
stretch (security) | 1.1.0l-1~deb9u6 | fixed | |
stretch (lts), stretch | 1.1.0l-1~deb9u10 | fixed | |
buster, buster (lts) | 1.1.1n-0+deb10u7 | fixed | |
buster (security) | 1.1.1n-0+deb10u6 | fixed | |
bullseye | 1.1.1w-0+deb11u1 | fixed | |
bullseye (security) | 1.1.1w-0+deb11u2 | fixed | |
bookworm | 3.0.15-1~deb12u1 | fixed | |
bookworm (security) | 3.0.14-1~deb12u2 | fixed | |
sid, trixie | 3.3.2-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
openssl | source | woody | 0.9.6c-2.woody.8 | DSA-888-1 | ||
openssl | source | sarge | 0.9.7e-3sarge1 | DSA-888-1 | ||
openssl | source | (unstable) | 0.9.8-3 | low | 333500 | |
openssl094 | source | woody | 0.9.4-6.woody.4 | DSA-875-1 | ||
openssl094 | source | (unstable) | (unfixed) | |||
openssl095 | source | woody | 0.9.5a-6.woody.6 | DSA-882-1 | ||
openssl095 | source | (unstable) | (unfixed) | |||
openssl096 | source | sarge | 0.9.6m-1sarge1 | DSA-881-1 | ||
openssl096 | source | (unstable) | (unfixed) | |||
openssl097 | source | (unstable) | 0.9.7g-5 | low | 333500 |