Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenSSL不安全的协议协商漏洞
Vulnerability Description
OpenSSL是OpenSSL团队开发的一个开源的能够实现安全套接层(SSL v2/v3)和安全传输层(TLS v1)协议的通用加密库,它支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 为了能与Microsoft Internet Explorer 3.02完全兼容,可以在OpenSSL中使用SL_OP_MSIE_SSLV2_RSA_PADDING选项禁用安全套接字层协议所需的验证步骤。常用的SSL_OP_ALL选项中包含有上述选项。 如果使用OpenSSL的应用服务器启用了SSL_OP_MS
CVSS Information
N/A
Vulnerability Type
N/A