UBUNTU-CVE-2015-4000
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-4000
UBUNTU-CVE-2015-4000
Summary:
Details: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
References: https://ubuntu.com/security/CVE-2015-4000, https://weakdh.org/imperfect-forward-secrecy.pdf, https://weakdh.org/, https://nohats.ca/wordpress/blog/2015/05/20/weakdh-and-ike-ipsec/, https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/, http://lists.gnutls.org/pipermail/gnutls-devel/2015-May/007597.html, https://access.redhat.com/articles/1456263, https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/LogJam, https://ubuntu.com/security/notices/USN-2624-1, https://ubuntu.com/security/notices/USN-2625-1, https://ubuntu.com/security/notices/USN-2639-1, https://ubuntu.com/security/notices/USN-2656-1, https://ubuntu.com/security/notices/USN-2656-2, https://ubuntu.com/security/notices/USN-2673-1, https://ubuntu.com/security/notices/USN-2696-1, https://ubuntu.com/security/notices/USN-2706-1, https://www.cve.org/CVERecord?id=CVE-2015-4000
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/firefox?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
