'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2019-12-25 | |
| Rule Name: | SSL 3.0 Padding Oracle Information Disclosure Vulnerability -2 (CVE-2014-3566) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Impact: | An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information. | |
| Affected OS: | Windows, Others | |
| Reference: | SecurityFocusBID:70574 SecurityTrackerID:1031039 SecurityTrackerID:1031086 SecurityTrackerID:1031088 SecurityTrackerID:1031090 SecurityTrackerID:1031092 SecurityTrackerID:1031094 SecurityTrackerID:1031096 SecurityTrackerID:1031106 SecurityTrackerID:1031120 SecurityTrackerID:1031124 SecurityTrackerID:1031131 MicrosoftSecurityBulletin:3009008 |
|
| Solutions |
|---|
| The vendors have released upgrade patches to fix vulnerabilities, please visit: https://www.openssl.org/news/ |