VDB
RHSA-2015%3A0800
RHSA-2015%3A0800
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Red Hat Security Advisory: openssl security update
Risk Scores
CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:enterprise_linux:5::client_workstation | openssl-debuginfo | 0, 0 |
| Red Hat:enterprise_linux:5::client | openssl-debuginfo | 0, 0 |
| Red Hat:enterprise_linux:5::server | openssl-debuginfo | 0, 0 |
| Red Hat:enterprise_linux:5::server | openssl-perl | 0, 0 |
| Red Hat:enterprise_linux:5::client_workstation | openssl | 0, 0 |
| Red Hat:enterprise_linux:5::server | openssl-devel | 0, 0 |
| Red Hat:enterprise_linux:5::client | openssl-perl | 0, 0 |
| Red Hat:enterprise_linux:5::client | openssl | 0, 0 |
| Red Hat:enterprise_linux:5::client_workstation | openssl-devel | 0, 0 |
| Red Hat:enterprise_linux:5::client_workstation | openssl-perl | 0, 0 |
| Red Hat:enterprise_linux:5::client | openssl-devel | 0, 0 |
| Red Hat:enterprise_linux:5::server | openssl | 0, 0 |
Exploit Intelligence
- This script check if your list of server is accepting Export cipher suites and could be vulnerable to CVE-2015-0204 (github-poc-repo)
- This script check if your list of server is accepting Export cipher suites and could be vulnerable to CVE-2015-0204 (github-poc-repo)
- Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204 (github-poc-repo)
- Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204 (github-poc-repo)
- Basic BASH Script to Automate OpenSSL based testing for FREAK Attack (CVE-2015-0204) as advised by Akamai. (github-poc-repo)
- Basic BASH Script to Automate OpenSSL based testing for FREAK Attack (CVE-2015-0204) as advised by Akamai. (github-poc-repo)
- A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous Cipher [CVE-2012-4929] CRIME(SPDY) [CVE-2014-0160] CCS Injection [CVE-2014-0224] HeartBleed [CVE-2014-3566] SSLv3 POODLE [CVE-2015-0204] FREAK Attack [CVE-2015-4000] LOGJAM Attack [CVE-2016-0800] SSLv2 DROWN Installation : $ apt update && apt upgrade $ apt install git $ apt install python2 $ apt install python $ git clone https://github.com/hahwul/ a2... (github-poc-repo)
- A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous Cipher [CVE-2012-4929] CRIME(SPDY) [CVE-2014-0160] CCS Injection [CVE-2014-0224] HeartBleed [CVE-2014-3566] SSLv3 POODLE [CVE-2015-0204] FREAK Attack [CVE-2015-4000] LOGJAM Attack [CVE-2016-0800] SSLv2 DROWN Installation : $ apt update && apt upgrade $ apt install git $ apt install python2 $ apt install python $ git clone https://github.com/hahwul/ a2... (github-poc-repo)
- Performs a testssl.sh test on SSL/TLS port and displays tool output. (nmap-nse)
- Performs a testssl.sh test on SSL/TLS port and displays tool output. (nmap-nse)
…and 2 more exploits
Timeline
- Apr 13, 2015 CVE Published
- Jul 7, 2016 PoC Published
- Apr 11, 2025 PoC Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2015:0800 advisory
- https://access.redhat.com/security/updates/classification/#moderate article
- https://www.openssl.org/news/secadv_20150108.txt article
- https://www.openssl.org/news/secadv_20150319.txt article
- https://access.redhat.com/articles/1384453 article
- https://bugzilla.redhat.com/show_bug.cgi?id=1180184 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1180187 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1202380 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1202384 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1202395 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1202404 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1202418 report
- https://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_0800.json advisory
- https://access.redhat.com/security/cve/CVE-2014-8275 report
- https://www.cve.org/CVERecord?id=CVE-2014-8275 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-8275 advisory
- https://access.redhat.com/security/cve/CVE-2015-0204 report
- https://www.cve.org/CVERecord?id=CVE-2015-0204 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-0204 advisory
- https://securityblog.redhat.com/2015/03/04/factoring-rsa-export-keys-freak-cve-2015-0204/ article
…and 25 more