CVE
- Id
- 46836
- CVE No.
- CVE-2010-4252
- Status
- Candidate
- Description
- OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.
- Phase
- Assigned (20101116)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
511809 | 46836 | CVE-2010-4252 | MISC:http://seb.dbzteam.org/crypto/jpake-session-key-retrieval.pdf | View |
511810 | 46836 | CVE-2010-4252 | MISC:https://github.com/seb-m/jpake | View |
511811 | 46836 | CVE-2010-4252 | CONFIRM:http://cvs.openssl.org/chngview?cn=20098 | View |
511812 | 46836 | CVE-2010-4252 | CONFIRM:http://openssl.org/news/secadv_20101202.txt | View |
511813 | 46836 | CVE-2010-4252 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=659297 | View |
511814 | 46836 | CVE-2010-4252 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 | View |
511815 | 46836 | CVE-2010-4252 | HP:HPSBOV02670 | View |
511816 | 46836 | CVE-2010-4252 | URL:http://marc.info/?l=bugtraq&m=130497251507577&w=2 | View |
511817 | 46836 | CVE-2010-4252 | HP:HPSBUX02638 | View |
511818 | 46836 | CVE-2010-4252 | URL:http://marc.info/?l=bugtraq&m=129916880600544&w=2 | View |
511819 | 46836 | CVE-2010-4252 | HP:SSRT100339 | View |
511820 | 46836 | CVE-2010-4252 | URL:http://marc.info/?l=bugtraq&m=129916880600544&w=2 | View |
511821 | 46836 | CVE-2010-4252 | HP:SSRT100475 | View |
511822 | 46836 | CVE-2010-4252 | URL:http://marc.info/?l=bugtraq&m=130497251507577&w=2 | View |
511823 | 46836 | CVE-2010-4252 | SLACKWARE:SSA:2010-340-01 | View |
511824 | 46836 | CVE-2010-4252 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668471 | View |
511825 | 46836 | CVE-2010-4252 | BID:45163 | View |
511826 | 46836 | CVE-2010-4252 | URL:http://www.securityfocus.com/bid/45163 | View |
511827 | 46836 | CVE-2010-4252 | OVAL:oval:org.mitre.oval:def:19039 | View |
511828 | 46836 | CVE-2010-4252 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19039 | View |
511829 | 46836 | CVE-2010-4252 | SECTRACK:1024823 | View |
511830 | 46836 | CVE-2010-4252 | URL:http://securitytracker.com/id?1024823 | View |
511831 | 46836 | CVE-2010-4252 | SECUNIA:42469 | View |
511832 | 46836 | CVE-2010-4252 | URL:http://secunia.com/advisories/42469 | View |
511833 | 46836 | CVE-2010-4252 | SECUNIA:57353 | View |
511834 | 46836 | CVE-2010-4252 | URL:http://secunia.com/advisories/57353 | View |
511835 | 46836 | CVE-2010-4252 | VUPEN:ADV-2010-3120 | View |
511836 | 46836 | CVE-2010-4252 | URL:http://www.vupen.com/english/advisories/2010/3120 | View |
511837 | 46836 | CVE-2010-4252 | VUPEN:ADV-2010-3122 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
33652 | JVNDB-2011-003894 | Linux kernel の pipe_fcntl 関数におけるサービス運用妨害 (DoS) の脆弱性 | Linux kernel の fs/pipe.cの pipe_fcntl 関数は、ファイルが名前付きパイプであるかを適切に判断しないため、サービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2010-4256 | 46836 | 4.9 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-003894.html | View |