Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XySSL ssl_parse_client_key_exchange函数权限许可和访问控制漏洞
Vulnerability Description
XySSL 0.9之前版本中的ssl_parse_client_key_exchange函数没有使用暗记文对抗特定的Bleichenbacher攻击,这使得远程攻击者可以借助未明向量,发现keys。
CVSS Information
N/A
Vulnerability Type
N/A