SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | google-chrome-upgrade-latest | May 3, 2018 | Oct 14, 2016 | |
| Suse | — | suse-upgrade-gitsuse-upgrade-git-archsuse-upgrade-git-coresuse-upgrade-git-cvssuse-upgrade-git-daemonsuse-upgrade-git-docsuse-upgrade-git-emailsuse-upgrade-git-guisuse-upgrade-git-svnsuse-upgrade-git-websuse-upgrade-gitksuse-upgrade-libgit2-1_3suse-upgrade-libgit2-26suse-upgrade-libgit2-28suse-upgrade-libgit2-develsuse-upgrade-libsha1detectcoll-develsuse-upgrade-libsha1detectcoll1suse-upgrade-perl-git | Aug 9, 2024 | Oct 14, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub