Description
The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3125-1 | openssl security update |
Ubuntu USN |
USN-2459-1 | OpenSSL vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T04:03:10.459Z
Reserved: 2014-11-18T00:00:00.000Z
Link: CVE-2015-0205
No data.
Status : Modified
Published: 2015-01-09T02:59:11.273
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-0205
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN