vulnerability

Ubuntu: (Multiple Advisories) (CVE-2015-7575): OpenSSL vulnerability

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jan 8, 2016
Added
Feb 2, 2016
Modified
Apr 14, 2025

Description

Karthikeyan Bhargavan and Gaetan Leurent discovered that OpenSSL
incorrectly allowed MD5 to be used for TLS 1.2 connections. If a remote
attacker were able to perform a machine-in-the-middle attack, this flaw could
be exploited to view sensitive information.

Solutions

ubuntu-upgrade-firefoxubuntu-upgrade-icedtea-7-jre-jamvmubuntu-upgrade-libgnutls-deb0-28ubuntu-upgrade-libgnutls-openssl27ubuntu-upgrade-libgnutls26ubuntu-upgrade-libgnutlsxx27ubuntu-upgrade-libgnutlsxx28ubuntu-upgrade-libnss3ubuntu-upgrade-libssl1-0-0ubuntu-upgrade-openjdk-7-jreubuntu-upgrade-openjdk-7-jre-headlessubuntu-upgrade-openjdk-7-jre-libubuntu-upgrade-openjdk-7-jre-zeroubuntu-upgrade-thunderbird

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.