SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | — | Upgrade to the latest version of Google Chrome | May 3, 2018 | Oct 14, 2016 |
| Suse | — | Upgrade git-cvsUpgrade git-credential-libsecretUpgrade gitkUpgrade gitUpgrade libgit2-26Upgrade libsha1detectcoll1Upgrade git-emailUpgrade git-webUpgrade git-svnUpgrade git-archUpgrade libgit2-1_7Upgrade perl-GitUpgrade git-docUpgrade libgit2-28Upgrade git-guiUpgrade git-daemonUpgrade libgit2-1_9Upgrade libgit2-toolsUpgrade libgit2-develUpgrade sha1collisiondetectionUpgrade git-p4Upgrade git-coreUpgrade libsha1detectcoll-develUpgrade libgit2-1_3 | Aug 9, 2024 | Oct 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub