OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Oct 18, 2014 |
| Apple Osx Afpserver | — | Apply Apple macOS Security Update 2015-001 | Aug 28, 2015 | Oct 18, 2014 |
| Apple Osx Openssl | — | Apply Apple macOS Security Update 2015-001Upgrade macOS to the latest version | Mar 29, 2016 | Oct 18, 2014 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Oct 19, 2014 |
| Freebsd | — | Upgrade opensslUpgrade FreeBSDUpgrade mingw32-opensslUpgrade linux-c6-openssl | Dec 10, 2025 | Oct 15, 2014 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Oct 18, 2014 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Oct 18, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Oct 18, 2014 |
| Hpux | — | Update openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-MAN to the latest version | Aug 11, 2017 | Oct 18, 2014 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Oct 19, 2014 | Oct 19, 2014 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.1.10-0.175.2.4.0.4.0 on Solaris 11.2Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.4.0.4.0 on Solaris 11.2 | May 29, 2017 | Oct 18, 2014 |
| Suse | — | Upgrade opensslUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0Upgrade libopenssl1_1-32bitUpgrade libopenssl0_9_8-32bitUpgrade libopenssl10Upgrade libopenssl-1_0_0-develUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-develUpgrade openssl-1_0_0Upgrade libopenssl-1_1-develUpgrade libopenssl1_0_0-hmac-32bitUpgrade openssl-docUpgrade libopenssl1_0_0-x86Upgrade libopenssl0_9_8Upgrade libopenssl1_0_0-hmacUpgrade libopenssl1_0_0-32bitUpgrade openssl1-docUpgrade libopenssl1_1-hmacUpgrade openssl1Upgrade compat-openssl097gUpgrade openssl-1_1Upgrade libopenssl0_9_8-x86Upgrade libopenssl0_9_8-hmacUpgrade libopenssl1_1Upgrade compat-openssl097g-32bitUpgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1-develUpgrade openssl-1_0_0-doc | Dec 18, 2015 | Oct 18, 2014 |
| Ubuntu | — | Upgrade openssl | Nov 19, 2024 | Oct 19, 2014 |
| Vmsa 2015 0001 | — | Upgrade VMware ESXi 5.0 to build number 2486588Upgrade VMware ESXi 5.5 to build number 2352327Upgrade VMware ESXi 5.1 to build number 2575044 | Apr 8, 2019 | Oct 18, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub