CVE-2010-4180: OpenSSL vulnerability, NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack

Solution Verified - Updated -

Issue

OpenSSL SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG Session Resume Ciphersuite Downgrade Weakness

Synopsis:
The remote host allows resuming SSL sessions.

Description:
The version of OpenSSL on the remote host has been shown to allow resuming session with a different cipher than was used when the session was initiated. This means that an attacker that sees (i.e., by sniffing) the start of an SSL connection can manipulate the OpenSSL session cache to cause subsequent resumes of that session to use a weaker cipher chosen by the attacker. Note that other SSL implementations may also be affected by this vulnerability.

Risk factor:
Medium

Environment

Red Hat Enterprise Linux version 4, 5, 6 (openssl)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content