CVE-2011-3389

SOURCE - nist

Summary

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

EPSS Score: 0.00854 (0.822)

Common Weakness Enumeration (CWE)

SOURCE - nist

Inadequate Encryption Strength


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/gnutls28debdebian12>=3.7.9-2+deb12u2Not yet available
debian/asteriskdebdebian11<1:13.7.2~dfsg-11:13.7.2~dfsg-1
debian/asteriskdebdebianunstable<1:13.7.2~dfsg-11:13.7.2~dfsg-1
debian/asteriskdebdebian10<1:13.7.2~dfsg-11:13.7.2~dfsg-1
debian/bouncycastledebdebian12<1.49+dfsg-11.49+dfsg-1
debian/bouncycastledebdebian13<1.49+dfsg-11.49+dfsg-1
debian/bouncycastledebdebian10<1.49+dfsg-11.49+dfsg-1
debian/bouncycastledebdebian11<1.49+dfsg-11.49+dfsg-1
debian/bouncycastledebdebianunstable<1.49+dfsg-11.49+dfsg-1
debian/curldebdebian10<7.24.0-17.24.0-1
debian/curldebdebian13<7.24.0-17.24.0-1
debian/curldebdebian12<7.24.0-17.24.0-1
debian/curldebdebianunstable<7.24.0-17.24.0-1
debian/curldebdebian11<7.24.0-17.24.0-1
debian/erlangdebdebian10<1:15.b-dfsg-11:15.b-dfsg-1
debian/erlangdebdebian12<1:15.b-dfsg-11:15.b-dfsg-1
debian/erlangdebdebian13<1:15.b-dfsg-11:15.b-dfsg-1
debian/erlangdebdebian11<1:15.b-dfsg-11:15.b-dfsg-1
debian/erlangdebdebianunstable<1:15.b-dfsg-11:15.b-dfsg-1
debian/gnutls28debdebian13>=3.8.5-2Not yet available
debian/gnutls28debdebian10>=3.6.7-4+deb10u8Not yet available
debian/gnutls28debdebian11>=3.7.1-5+deb11u4Not yet available
debian/gnutls28debdebianunstable>=3.8.5-2Not yet available
debian/haskell-tlsdebdebian13>=1.6.0-1Not yet available
debian/haskell-tlsdebdebian10>=1.4.1-3Not yet available
debian/haskell-tlsdebdebianunstable>=1.6.0-1Not yet available
debian/haskell-tlsdebdebian12>=1.5.8-1Not yet available
debian/haskell-tlsdebdebian11>=1.5.4-1Not yet available
debian/lighttpddebdebian11<1.4.30-11.4.30-1
debian/lighttpddebdebianunstable<1.4.30-11.4.30-1
debian/lighttpddebdebian13<1.4.30-11.4.30-1
debian/lighttpddebdebian12<1.4.30-11.4.30-1
debian/lighttpddebdebian10<1.4.30-11.4.30-1
debian/nssdebdebian11<3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
debian/nssdebdebian10<3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
debian/nssdebdebian13<3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
debian/nssdebdebianunstable<3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
debian/nssdebdebian12<3.13.1.with.ckbi.1.88-13.13.1.with.ckbi.1.88-1
debian/pounddebdebian11<2.6-22.6-2
debian/python2.7debdebian10<2.7.3~rc1-12.7.3~rc1-1
debian/python2.7debdebian11<2.7.3~rc1-12.7.3~rc1-1

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

8.6


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

4.3medium

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

amazon

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Acritical

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

8.6


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

4.3medium

suse

CREATED


UPDATED



EXPLOITABILITY SCORE

2.2


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

3.7medium

oracle

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Acritical

chainguard

CREATED


UPDATED


SOURCE ID

CVE-2011-3389


EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

wolfi

CREATED


UPDATED


SOURCE ID

CVE-2011-3389


EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE