Protokół SSL 3.0 używany w OpenSSL do wersji 1.0.1i i innych produktach wykorzystuje niedeterministyczne padding CBC, co ułatwia atacjnikom typu man-in-the-middle uzyskanie danych w czystym tekście poprzez atak padding-oracle, znany jako luka "POODLE".
▸ Pokaż oryginał (EN)
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:NApple Mac Os X
OSApple≤ 10.10.1Fedora Project Fedora
OSFedoraproject192021IBM Aix
OSIbm5.36.17.1IBM Vios
APPIbm2.2.0.102.2.0.112.2.0.122.2.0.132.2.1.02.2.1.12.2.1.32.2.1.42.2.1.52.2.1.62.2.1.72.2.1.82.2.1.9Mageia
OSMageia3.04.0Novell SUSE Linux Enterprise Desktop
OSNovell10.011.012.09.0Novell SUSE Linux Enterprise Server
OSNovell11.012.0Novell SUSE Linux Enterprise Software Development Kit
APPNovell11.012.0OpenSSL
APPOpenssl0.9.80.9.8a0.9.8b0.9.8c0.9.8d0.9.8e0.9.8f0.9.8g0.9.8h0.9.8i0.9.8j0.9.8k0.9.8l0.9.8m0.9.8n+ 39 więcejOpensuse
OSOpensuse12.313.1Red Hat Enterprise Linux
OSRedhat5Red Hat Enterprise Linux Desktop
OSRedhat6.07.0Red Hat Enterprise Linux Desktop Supplementary
OSRedhat5.06.0Red Hat Enterprise Linux Server
OSRedhat6.07.0Red Hat Enterprise Linux Server Supplementary
OSRedhat5.06.07.0Red Hat Enterprise Linux Workstation
OSRedhat6.07.0Red Hat Enterprise Linux Workstation Supplementary
OSRedhat6.07.0
Powiązane podatności
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox