OpenSSL Ciphersuite Downgrade Security Weakness

  Bookmark
 and Share

OpenSSL is an open source cryptography library. OpenSSL is exposed to a security weakness that may allow attackers to downgrade the ciphersuite. Specifically, this issue is due to old workaround code included in the server that may allow attackers to modify the stored session cache ciphersuite. Releases prior to OpenSSL 1.0.0c are affected.

Ref: http://www.securityfocus.com/bid/45164

10.50.27 - CVE: CVE-2010-4180, CVE-2010-4252
Platform: Cross Platform