UBUNTU-CVE-2014-3566
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3566
UBUNTU-CVE-2014-3566
Summary:
Details: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
References: https://ubuntu.com/security/CVE-2014-3566, https://www.openssl.org/~bodo/ssl-poodle.pdf, https://www.imperialviolet.org/2014/10/14/poodle.html, http://marc.info/?l=openssl-dev&m=141333049205629&w=2, https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/, https://www.openssl.org/news/secadv_20141015.txt, http://askubuntu.com/a/537196, https://ubuntu.com/security/notices/USN-2486-1, https://ubuntu.com/security/notices/USN-2487-1, https://www.cve.org/CVERecord?id=CVE-2014-3566
Affected packages
Package
Name: openjdk-6
Purl: pkg:deb/ubuntu/openjdk-6?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
