Navigation und Service

CB-K13/0093 Update 26

Risikostufe 3

Titel:SSL, TLS, DTLS: Schwachstelle ermöglicht Umgehen von SicherheitsvorkehrungenDatum:11.04.2022Software:Open Source GnuTLS < 2.12.23, Open Source GnuTLS < 3.0.28, Open Source GnuTLS < 3.1.7, Open Source OpenSSL <= 1.0.1c, Opera Opera Browser < 12.13, F5 ARX 5.3.1, F5 ARX 6.3.0, F5 Advanced Firewall Manager 11.3.0, F5 BIG-IP Access Policy Manager 10.2.4, F5 BIG-IP Access Policy Manager 11.3.0, F5 BIG-IP Analytics 11.3.0, F5 BIG-IP Application Security Manager 10.2.4, F5 BIG-IP Application Security Manager 11.3.0, F5 BIG-IP Application Security Manager 9.4.8, F5 BIG-IP Edge Gateway 10.2.4, F5 BIG-IP Edge Gateway 11.3.0, F5 BIG-IP Global Traffic Manager 10.2.4, F5 BIG-IP Global Traffic Manager 11.3.0, F5 BIG-IP Global Traffic Manager 9.4.8, F5 BIG-IP Link Controller 10.2.4, F5 BIG-IP Link Controller 11.3.0, F5 BIG-IP Link Controller 9.4.8, F5 BIG-IP Local Traffic Manager 10.2.4, F5 BIG-IP Local Traffic Manager 11.3.0, F5 BIG-IP Local Traffic Manager 9.6.1, F5 BIG-IP Protocol Security Manager 10.2.4, F5 BIG-IP Protocol Security Manager 11.3.0, F5 BIG-IP Protocol Security Manager 9.4.8, F5 Enterprise Manager 1.8.0, F5 Policy Enforcement Manager 11.3.0, F5 WAN Optimization Manager 10.2.4, F5 WAN Optimization Manager 11.3.0, F5 WebAccelerator 10.2.4, F5 WebAccelerator 11.3.0, F5 WebAccelerator 9.4.8, IBM HTTP Server 6.1.0.0 - 6.1.0.45, IBM HTTP Server 7.0.0.0 - 7.0.0.27, IBM HTTP Server 8.0.0.0 - 8.0.0.6, IBM HTTP Server 8.5.0.0 - 8.5.0.2, IBM Tivoli Directory Server < 6.0.0.72, IBM Tivoli Directory Server < 6.1.0.55, IBM Tivoli Directory Server < 6.2.0.30, IBM Tivoli Directory Server < 6.3.0.22, IBM WebSphere Application Server 6.1.0.0 - 6.1.0.45, IBM WebSphere Application Server 7.0.0.0 - 7.0.0.27, IBM WebSphere Application Server 8.0.0.0 - 8.0.0.6, IBM WebSphere Application Server 8.5.0.0 - 8.5.0.2, IBM Spectrum Protect 5.5, IBM Spectrum Protect 6.1, IBM Spectrum Protect 6.2, IBM Spectrum Protect 6.3, SUSE Linux, Oracle Solaris 10, Oracle Solaris 11.1, Oracle Solaris 8, Oracle Solaris 9, Arista EOS <= 4.15, Splunk Splunk Enterprise 6.0.12, Splunk Splunk Enterprise 6.1.11, Splunk Splunk Enterprise 6.4.2, Oracle LinuxPlattform:Applicance, Linux, UNIX, WindowsAuswirkung:Umgehen von SicherheitsvorkehrungenRemoteangriff:JaRisiko:mittelCVE Liste:CVE-2013-0169, CVE-2013-1618, CVE-2013-1619, CVE-2013-1620Bezug:

Beschreibung

GnuTLS (GNU Transport Layer Security Library) ist eine im Quelltext frei verfügbare Bibliothek, die Secure Sockets Layer (SSL) und Transport Layer Security (TLS) implementiert. OpenSSL ist eine im Quelltext frei verfügbare Bibliothek, die Secure Sockets Layer (SSL) und Transport Layer Security (TLS) implementiert.

Ein entfernter, anonymer Angreifer aus dem lokalen Netzwerk kann eine Schwachstelle in SSL, TLS und DTLS ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

Quellen: