Is there any solution to CVE-2013-2566

Latest response

Hello everybody,

is there any solution to this issue CVE-2013-2566 SSL/TLS: Attack against RC4 stream cipher

Thanks

Responses

What type of "solution" are you looking for? Per Red Hat's publication on the issue, the problem's in the encryption suite, itself. Best "solution" you're likely to find is "disable the use of RC4 in your services".

See also https://access.redhat.com/solutions/345403 (Is there any resolution for TLS/SSL RC4 vulnerability (CVE-2013-2566)?), which describes how to change the cipher order, so that other ciphers than RC4 are preferred in case you don't want to disable it altogether.

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.