SB2016092301 - Information disclosure in OpenBSD libssl
Published: September 23, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Weak encryption (CVE-ID: N/A)
A remote attacker can gain access to potentially sensitive information.
The vulnerability exists in SSL_set_SSL_CTX() function in lib/libssl/src/ssl/ssl_lib.c. A remote attacker can force the encrypted connection to fall back to weak digest for (EC)DH when using SNI with libssl.
Successful exploitation of the vulnerability will allow an attacker to gain access to potentially sensitive data.
Remediation
Install update from vendor's website.