CVE-2010-4180
Summary
| CVE | CVE-2010-4180 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-06 21:05:48 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Blue Coat CacheFlow OpenSSL Ciphersuite Downgrade Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian -- Security Information -- DSA-2141-1 openssl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| OpenSSL Stored Session Cache Modification Bug May Let Remote Users Downgrade the Ciphersuite - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| OpenSSL Ciphersuite Downgrade Security Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 13 Update: openssl-1.0.0c-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| SUSE update for multiple packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Bug 659462 – CVE-2010-4180 openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Blue Coat Director OpenSSL Ciphersuite Downgrade Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| cvs.openssl.org/chngview | af854a3a-2127-422b-91ae-364da2661108 | cvs.openssl.org | Broken Link, Patch |
| openssl.org/news/secadv_20101202.txt | af854a3a-2127-422b-91ae-364da2661108 | openssl.org | Patch, Third Party Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:009 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Blue Coat ProxySG OpenSSL Ciphersuite Downgrade Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| USN-1029-1: OpenSSL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| [security-announce] openSUSE-SU-2011:0845-1: important: compat-openssl09 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | Broken Link |
| Ubuntu update for openssl - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Fedora update for openssl - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| About the security content of Mac OS X v10.6.8 and Security Update 2011-004 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| APPLE-SA-2011-06-23-1 Mac OS X v10.6.8 and Security Update 2011-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Broken Link, Mailing List, Third Party Advisory |
| Red Hat update for openssl - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Bluecoat Knowledge Base | af854a3a-2127-422b-91ae-364da2661108 | kb.bluecoat.com | Broken Link |
| Blue Coat ProxyAV OpenSSL Ciphersuite Downgrade Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Slackware update for openssl - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| [SECURITY] Fedora 14 Update: openssl-1.0.0c-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Blue Coat ProxyOne OpenSSL Ciphersuite Downgrade Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Vulnerability Note VU#737740 - Fiery Network Controllers for Xerox DocuColor 242/252/260 Printer/Copier use a vulnerable version of OpenSSL | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| '[security bulletin] HPSBOV02670 SSRT100475 rev.1 - HP OpenVMS running SSL, Remote Denial of Service' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Issue Tracking, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Debian update for openssl - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Support / Security / Advisories / / MDVSA-2010:248 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Permissions Required |
| '[security bulletin] HPSBHF02706 SSRT100613 rev.1 - HP Integrated Lights-Out iLO2 and iLO3 running SS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Issue Tracking, Third Party Advisory |
| '[security bulletin] HPSBUX02638 SSRT100339 rev.1 - HP-UX Running OpenSSL, Remote Execution of Arbitr' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Issue Tracking, Third Party Advisory |
| osvdb.org/69565 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| HP Insight Control for Linux Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| [security-announce] SUSE-SU-2011:0847-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| OpenSSL "NETSCAPE_REUSE_CIPHER_CHANGE_BUG" Ciphersuite Downgrade Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:001 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.