oval:org.mitre.oval:def:10088

Definition Id: oval:org.mitre.oval:def:10088
 
Oval ID: oval:org.mitre.oval:def:10088
Title: The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Description: The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Family: unix Class: vulnerability
Reference(s): CVE-2009-3555
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:11831
 
Oval ID: oval:org.mitre.oval:def:11831
Title: The operating system installed on the system is Red Hat Enterprise Linux 4
Description: The operating system installed on the system is Red Hat Enterprise Linux 4.
Family: unix Class: inventory
Reference(s): cpe:/o:redhat:enterprise_linux:4
Version: 7
Platform(s): Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:16636
 
Oval ID: oval:org.mitre.oval:def:16636
Title: CentOS Linux 4.x
Description: The operating system installed on the system is CentOS Linux 4.x
Family: unix Class: inventory
Reference(s): cpe:/o:centos:centos:4
Version: 3
Platform(s): CentOS Linux 4
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:15990
 
Oval ID: oval:org.mitre.oval:def:15990
Title: Oracle Linux 4.x
Description: The operating system installed on the system is Oracle Linux 4.x
Family: unix Class: inventory
Reference(s): cpe:/o:oracle:linux:4
Version: 5
Platform(s): Oracle Linux 4
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:11414
 
Oval ID: oval:org.mitre.oval:def:11414
Title: The operating system installed on the system is Red Hat Enterprise Linux 5
Description: The operating system installed on the system is Red Hat Enterprise Linux 5.
Family: unix Class: inventory
Reference(s): cpe:/o:redhat:enterprise_linux:5
Version: 7
Platform(s): Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:15802
 
Oval ID: oval:org.mitre.oval:def:15802
Title: The operating system installed on the system is CentOS Linux 5.x
Description: The operating system installed on the system is CentOS Linux 5.x
Family: unix Class: inventory
Reference(s): cpe:/o:centos:centos:5
Version: 7
Platform(s): CentOS Linux 5
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:15459
 
Oval ID: oval:org.mitre.oval:def:15459
Title: Oracle Linux 5.x
Description: The operating system installed on the system is Oracle Linux 5.x
Family: unix Class: inventory
Reference(s): cpe:/o:oracle:linux:5
Version: 7
Platform(s): Oracle Linux 5
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:11782
 
Oval ID: oval:org.mitre.oval:def:11782
Title: The operating system installed on the system is Red Hat Enterprise Linux 3
Description: The operating system installed on the system is Red Hat Enterprise Linux 3.
Family: unix Class: inventory
Reference(s): cpe:/o:redhat:enterprise_linux:3
Version: 7
Platform(s): Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088
Definition Id: oval:org.mitre.oval:def:16651
 
Oval ID: oval:org.mitre.oval:def:16651
Title: CentOS Linux 3.x
Description: The operating system installed on the system is CentOS Linux 3.x
Family: unix Class: inventory
Reference(s): cpe:/o:centos:centos:3
Version: 3
Platform(s): CentOS Linux 3
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:10088