mirror of
https://github.com/0xMarcio/cve.git
synced 2026-03-29 20:30:57 +02:00
1.2 KiB
1.2 KiB
CVE-2014-3511
Description
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.
POC
Reference
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-372998.htm
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- https://kc.mcafee.com/corporate/index?page=content&id=SB10084