Project

General

Profile

Actions

Bug #7632

closed

CVE-2016-2107 in OpenSSL

Added by Adrian James almost 7 years ago. Updated almost 7 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
06/08/2017
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
2.3.4
Affected Plus Version:
Affected Architecture:
amd64

Description

pfSense 2.3.4 uses OpenSSL 1.0.1s which is vulnerable to CVE-2016-2107 Oracle Padding attack. HAProxy TLS termination for front ends uses this and so makes services dependent on it vulnerable.

Actions

Also available in: Atom PDF