CVE-2009-3555
9.8 CRITICALThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in...
Published: 2009-11-09 · Last updated: 2026-05-27
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-295, CWE-300
Affected products
| Vendor | Product |
|---|---|
| apache | debian_linux, fedora, gnutls |
| canonical | debian_linux, fedora, gnutls |
| debian | debian_linux, fedora, gnutls |
| f5 | debian_linux, fedora, gnutls |
| fedoraproject | debian_linux, fedora, gnutls |
| gnu | debian_linux, fedora, gnutls |
| mozilla | debian_linux, fedora, gnutls |
| openssl | debian_linux, fedora, gnutls |
Description
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2009-3555
- [Other]http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html
- [Other]http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html
- [Other]http://blogs.iss.net/archive/sslmitmiscsrf.html
- [Other]http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during
- [Exploit reference]http://clicky.me/tlsvuln
- [Other]http://extendedsubset.com/?p=8
- [Other]http://extendedsubset.com/Renegotiating_TLS.pdf
- [Other]http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686
- [Other]http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041
- [Other]http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
- [Other]http://kbase.redhat.com/faq/docs/DOC-20491
- [Other]http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
- [Other]http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
- [Other]http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html
- [Other]http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html
- [Other]http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2
- [Other]http://marc.info/?l=bugtraq&m=126150535619567&w=2
- [Other]http://marc.info/?l=bugtraq&m=127128920008563&w=2
- [Other]http://marc.info/?l=bugtraq&m=127419602507642&w=2
- [Other]http://marc.info/?l=bugtraq&m=127557596201693&w=2
- [Other]http://marc.info/?l=bugtraq&m=130497311408250&w=2
- [Other]http://marc.info/?l=bugtraq&m=132077688910227&w=2
- [Other]http://marc.info/?l=bugtraq&m=133469267822771&w=2
- [Other]http://marc.info/?l=bugtraq&m=134254866602253&w=2
- [Other]http://marc.info/?l=bugtraq&m=142660345230545&w=2
- [Other]http://marc.info/?l=cryptography&m=125752275331877&w=2
- [Other]http://openbsd.org/errata45.html#010_openssl
- [Other]http://openbsd.org/errata46.html#004_openssl
- [Other]http://osvdb.org/60521
- [Other]http://osvdb.org/60972
- [Other]http://osvdb.org/62210
- [Other]http://osvdb.org/65202
- [Other]http://seclists.org/fulldisclosure/2009/Nov/139
- [Other]http://secunia.com/advisories/37291
- [Other]http://secunia.com/advisories/37292
- [Other]http://secunia.com/advisories/37320
- [Other]http://secunia.com/advisories/37383
- [Other]http://secunia.com/advisories/37399
- [Other]http://secunia.com/advisories/37453
- [Other]http://secunia.com/advisories/37501
- [Other]http://secunia.com/advisories/37504
- [Other]http://secunia.com/advisories/37604
- [Other]http://secunia.com/advisories/37640
- [Other]http://secunia.com/advisories/37656
- [Other]http://secunia.com/advisories/37675
- [Other]http://secunia.com/advisories/37859
- [Other]http://secunia.com/advisories/38003
- [Other]http://secunia.com/advisories/38020
- [Other]http://secunia.com/advisories/38056
- [Other]http://secunia.com/advisories/38241
- [Other]http://secunia.com/advisories/38484
- [Other]http://secunia.com/advisories/38687
- [Other]http://secunia.com/advisories/38781
- [Other]http://secunia.com/advisories/39127
- [Other]http://secunia.com/advisories/39136
- [Other]http://secunia.com/advisories/39242
- [Other]http://secunia.com/advisories/39243
- [Other]http://secunia.com/advisories/39278
- [Other]http://secunia.com/advisories/39292
- [Other]http://secunia.com/advisories/39317
- [Other]http://secunia.com/advisories/39461
- [Other]http://secunia.com/advisories/39500
- [Other]http://secunia.com/advisories/39628
- [Other]http://secunia.com/advisories/39632
- [Other]http://secunia.com/advisories/39713
- [Other]http://secunia.com/advisories/39819
- [Other]http://secunia.com/advisories/40070
- [Other]http://secunia.com/advisories/40545
- [Other]http://secunia.com/advisories/40747
- [Other]http://secunia.com/advisories/40866
- [Other]http://secunia.com/advisories/41480
- [Other]http://secunia.com/advisories/41490
- [Other]http://secunia.com/advisories/41818
- [Other]http://secunia.com/advisories/41967
- [Other]http://secunia.com/advisories/41972
- [Other]http://secunia.com/advisories/42377
- [Other]http://secunia.com/advisories/42379
- [Other]http://secunia.com/advisories/42467
- [Other]http://secunia.com/advisories/42724
- [Other]http://secunia.com/advisories/42733
- [Other]http://secunia.com/advisories/42808
- [Other]http://secunia.com/advisories/42811
- [Other]http://secunia.com/advisories/42816
- [Other]http://secunia.com/advisories/43308
- [Other]http://secunia.com/advisories/44183
- [Other]http://secunia.com/advisories/44954
- [Other]http://secunia.com/advisories/48577
- [Other]http://security.gentoo.org/glsa/glsa-200912-01.xml
- [Other]http://security.gentoo.org/glsa/glsa-201203-22.xml
- [Other]http://security.gentoo.org/glsa/glsa-201406-32.xml
- [Other]http://securitytracker.com/id?1023148
- [Other]http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1
- [Other]http://support.apple.com/kb/HT4004
- [Other]http://support.apple.com/kb/HT4170
- [Other]http://support.apple.com/kb/HT4171
- [Other]http://support.avaya.com/css/P8/documents/100070150
- [Other]http://support.avaya.com/css/P8/documents/100081611
- [Other]http://support.avaya.com/css/P8/documents/100114315
- [Other]http://support.avaya.com/css/P8/documents/100114327
- [Other]http://support.citrix.com/article/CTX123359
- [Other]http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES
- [Other]http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released
- [Other]http://sysoev.ru/nginx/patch.cve-2009-3555.txt
- [Other]http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html
- [Other]http://ubuntu.com/usn/usn-923-1
- [Other]http://wiki.rpath.com/Advisories:rPSA-2009-0155
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg21426108
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg21432298
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg24006386
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg24025312
- [Other]http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only
- [Other]http://www.arubanetworks.com/support/alerts/aid-020810.txt
- [Other]http://www.betanews.com/article/1257452450
- [Other]http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml
- [Other]http://www.debian.org/security/2009/dsa-1934
- [Other]http://www.debian.org/security/2011/dsa-2141
- [Other]http://www.debian.org/security/2015/dsa-3253
- [Other]http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html
- [Other]http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html
- [Other]http://www.ietf.org/mail-archive/web/tls/current/msg03928.html
- [Other]http://www.ietf.org/mail-archive/web/tls/current/msg03948.html
- [Other]http://www.ingate.com/Relnote.php?ver=481
- [Other]http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995
- [Other]http://www.kb.cert.org/vuls/id/120541
- [Other]http://www.links.org/?p=780
- [Other]http://www.links.org/?p=786
- [Other]http://www.links.org/?p=789
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:076
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:089
- [Other]http://www.mozilla.org/security/announce/2010/mfsa2010-22.html
- [Other]http://www.openoffice.org/security/cves/CVE-2009-3555.html
- [Other]http://www.openssl.org/news/secadv_20091111.txt
- [Other]http://www.openwall.com/lists/oss-security/2009/11/05/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/05/5
- [Other]http://www.openwall.com/lists/oss-security/2009/11/06/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/07/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/20/1
- [Other]http://www.openwall.com/lists/oss-security/2009/11/23/10
- [Other]http://www.opera.com/docs/changelogs/unix/1060/
- [Other]http://www.opera.com/support/search/view/944/
- [Other]http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
- [Other]http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- [Other]http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
- [Other]http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0119.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0130.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0155.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0165.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0167.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0337.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0338.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0339.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0768.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0770.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0786.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0807.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0865.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0986.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0987.html
- [Other]http://www.redhat.com/support/errata/RHSA-2011-0880.html
- [Other]http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html
- [Other]http://www.securityfocus.com/archive/1/507952/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/508075/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/508130/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/515055/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/516397/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/522176
- [Patch]http://www.securityfocus.com/bid/36935
- [Other]http://www.securitytracker.com/id?1023163
- [Other]http://www.securitytracker.com/id?1023204
- [Other]http://www.securitytracker.com/id?1023205
- [Other]http://www.securitytracker.com/id?1023206
- [Other]http://www.securitytracker.com/id?1023207
- [Other]http://www.securitytracker.com/id?1023208
- [Other]http://www.securitytracker.com/id?1023209
- [Other]http://www.securitytracker.com/id?1023210
- [Other]http://www.securitytracker.com/id?1023211
- [Other]http://www.securitytracker.com/id?1023212
- [Other]http://www.securitytracker.com/id?1023213
- [Other]http://www.securitytracker.com/id?1023214
- [Other]http://www.securitytracker.com/id?1023215
- [Other]http://www.securitytracker.com/id?1023216
- [Other]http://www.securitytracker.com/id?1023217
- [Other]http://www.securitytracker.com/id?1023218
- [Other]http://www.securitytracker.com/id?1023219
- [Other]http://www.securitytracker.com/id?1023224
- [Other]http://www.securitytracker.com/id?1023243
- [Other]http://www.securitytracker.com/id?1023270
- [Other]http://www.securitytracker.com/id?1023271
- [Other]http://www.securitytracker.com/id?1023272
- [Other]http://www.securitytracker.com/id?1023273
- [Other]http://www.securitytracker.com/id?1023274
- [Other]http://www.securitytracker.com/id?1023275
- [Other]http://www.securitytracker.com/id?1023411
- [Other]http://www.securitytracker.com/id?1023426
- [Other]http://www.securitytracker.com/id?1023427
- [Other]http://www.securitytracker.com/id?1023428
- [Other]http://www.securitytracker.com/id?1024789
- [Other]http://www.tombom.co.uk/blog/?p=85
- [Other]http://www.ubuntu.com/usn/USN-1010-1
- [Other]http://www.ubuntu.com/usn/USN-927-1
- [Other]http://www.ubuntu.com/usn/USN-927-4
- [Other]http://www.ubuntu.com/usn/USN-927-5
- [Other]http://www.us-cert.gov/cas/techalerts/TA10-222A.html
- [Other]http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- [Other]http://www.vmware.com/security/advisories/VMSA-2010-0019.html
- [Other]http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- [Other]http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
- [Other]http://www.vupen.com/english/advisories/2009/3164
- [Other]http://www.vupen.com/english/advisories/2009/3165
- [Other]http://www.vupen.com/english/advisories/2009/3205
- [Other]http://www.vupen.com/english/advisories/2009/3220
- [Other]http://www.vupen.com/english/advisories/2009/3310
- [Other]http://www.vupen.com/english/advisories/2009/3313
- [Other]http://www.vupen.com/english/advisories/2009/3353
- [Other]http://www.vupen.com/english/advisories/2009/3354
- [Other]http://www.vupen.com/english/advisories/2009/3484
- [Other]http://www.vupen.com/english/advisories/2009/3521
- [Other]http://www.vupen.com/english/advisories/2009/3587
- [Other]http://www.vupen.com/english/advisories/2010/0086
- [Other]http://www.vupen.com/english/advisories/2010/0173
- [Other]http://www.vupen.com/english/advisories/2010/0748
- [Other]http://www.vupen.com/english/advisories/2010/0848
- [Other]http://www.vupen.com/english/advisories/2010/0916
- [Other]http://www.vupen.com/english/advisories/2010/0933
- [Other]http://www.vupen.com/english/advisories/2010/0982
- [Other]http://www.vupen.com/english/advisories/2010/0994
- [Other]http://www.vupen.com/english/advisories/2010/1054
- [Other]http://www.vupen.com/english/advisories/2010/1107
- [Other]http://www.vupen.com/english/advisories/2010/1191
- [Other]http://www.vupen.com/english/advisories/2010/1350
- [Other]http://www.vupen.com/english/advisories/2010/1639
- [Other]http://www.vupen.com/english/advisories/2010/1673
- [Other]http://www.vupen.com/english/advisories/2010/1793
- [Other]http://www.vupen.com/english/advisories/2010/2010
- [Other]http://www.vupen.com/english/advisories/2010/2745
- [Other]http://www.vupen.com/english/advisories/2010/3069
- [Other]http://www.vupen.com/english/advisories/2010/3086
- [Other]http://www.vupen.com/english/advisories/2010/3126
- [Other]http://www.vupen.com/english/advisories/2011/0032
- [Other]http://www.vupen.com/english/advisories/2011/0033
- [Other]http://www.vupen.com/english/advisories/2011/0086
- [Exploit reference]http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=526689
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=545755
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=533125
- [Patch]https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049
- [Other]https://exchange.xforce.ibmcloud.com/vulnerabilities/54158
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- [Other]https://kb.bluecoat.com/index?page=content&id=SA50
- [Other]https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535
- [Other]https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html
- [Other]https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html
- [Other]http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html
- [Other]http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html
- [Other]http://blogs.iss.net/archive/sslmitmiscsrf.html
- [Other]http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during
- [Exploit reference]http://clicky.me/tlsvuln
- [Other]http://extendedsubset.com/?p=8
- [Other]http://extendedsubset.com/Renegotiating_TLS.pdf
- [Other]http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686
- [Other]http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041
- [Other]http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
- [Other]http://kbase.redhat.com/faq/docs/DOC-20491
- [Other]http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
- [Other]http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
- [Other]http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html
- [Other]http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html
- [Other]http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html
- [Other]http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html
- [Other]http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2
- [Other]http://marc.info/?l=bugtraq&m=126150535619567&w=2
- [Other]http://marc.info/?l=bugtraq&m=127128920008563&w=2
- [Other]http://marc.info/?l=bugtraq&m=127419602507642&w=2
- [Other]http://marc.info/?l=bugtraq&m=127557596201693&w=2
- [Other]http://marc.info/?l=bugtraq&m=130497311408250&w=2
- [Other]http://marc.info/?l=bugtraq&m=132077688910227&w=2
- [Other]http://marc.info/?l=bugtraq&m=133469267822771&w=2
- [Other]http://marc.info/?l=bugtraq&m=134254866602253&w=2
- [Other]http://marc.info/?l=bugtraq&m=142660345230545&w=2
- [Other]http://marc.info/?l=cryptography&m=125752275331877&w=2
- [Other]http://openbsd.org/errata45.html#010_openssl
- [Other]http://openbsd.org/errata46.html#004_openssl
- [Other]http://osvdb.org/60521
- [Other]http://osvdb.org/60972
- [Other]http://osvdb.org/62210
- [Other]http://osvdb.org/65202
- [Other]http://seclists.org/fulldisclosure/2009/Nov/139
- [Other]http://secunia.com/advisories/37291
- [Other]http://secunia.com/advisories/37292
- [Other]http://secunia.com/advisories/37320
- [Other]http://secunia.com/advisories/37383
- [Other]http://secunia.com/advisories/37399
- [Other]http://secunia.com/advisories/37453
- [Other]http://secunia.com/advisories/37501
- [Other]http://secunia.com/advisories/37504
- [Other]http://secunia.com/advisories/37604
- [Other]http://secunia.com/advisories/37640
- [Other]http://secunia.com/advisories/37656
- [Other]http://secunia.com/advisories/37675
- [Other]http://secunia.com/advisories/37859
- [Other]http://secunia.com/advisories/38003
- [Other]http://secunia.com/advisories/38020
- [Other]http://secunia.com/advisories/38056
- [Other]http://secunia.com/advisories/38241
- [Other]http://secunia.com/advisories/38484
- [Other]http://secunia.com/advisories/38687
- [Other]http://secunia.com/advisories/38781
- [Other]http://secunia.com/advisories/39127
- [Other]http://secunia.com/advisories/39136
- [Other]http://secunia.com/advisories/39242
- [Other]http://secunia.com/advisories/39243
- [Other]http://secunia.com/advisories/39278
- [Other]http://secunia.com/advisories/39292
- [Other]http://secunia.com/advisories/39317
- [Other]http://secunia.com/advisories/39461
- [Other]http://secunia.com/advisories/39500
- [Other]http://secunia.com/advisories/39628
- [Other]http://secunia.com/advisories/39632
- [Other]http://secunia.com/advisories/39713
- [Other]http://secunia.com/advisories/39819
- [Other]http://secunia.com/advisories/40070
- [Other]http://secunia.com/advisories/40545
- [Other]http://secunia.com/advisories/40747
- [Other]http://secunia.com/advisories/40866
- [Other]http://secunia.com/advisories/41480
- [Other]http://secunia.com/advisories/41490
- [Other]http://secunia.com/advisories/41818
- [Other]http://secunia.com/advisories/41967
- [Other]http://secunia.com/advisories/41972
- [Other]http://secunia.com/advisories/42377
- [Other]http://secunia.com/advisories/42379
- [Other]http://secunia.com/advisories/42467
- [Other]http://secunia.com/advisories/42724
- [Other]http://secunia.com/advisories/42733
- [Other]http://secunia.com/advisories/42808
- [Other]http://secunia.com/advisories/42811
- [Other]http://secunia.com/advisories/42816
- [Other]http://secunia.com/advisories/43308
- [Other]http://secunia.com/advisories/44183
- [Other]http://secunia.com/advisories/44954
- [Other]http://secunia.com/advisories/48577
- [Other]http://security.gentoo.org/glsa/glsa-200912-01.xml
- [Other]http://security.gentoo.org/glsa/glsa-201203-22.xml
- [Other]http://security.gentoo.org/glsa/glsa-201406-32.xml
- [Other]http://securitytracker.com/id?1023148
- [Other]http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1
- [Other]http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1
- [Other]http://support.apple.com/kb/HT4004
- [Other]http://support.apple.com/kb/HT4170
- [Other]http://support.apple.com/kb/HT4171
- [Other]http://support.avaya.com/css/P8/documents/100070150
- [Other]http://support.avaya.com/css/P8/documents/100081611
- [Other]http://support.avaya.com/css/P8/documents/100114315
- [Other]http://support.avaya.com/css/P8/documents/100114327
- [Other]http://support.citrix.com/article/CTX123359
- [Other]http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES
- [Other]http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released
- [Other]http://sysoev.ru/nginx/patch.cve-2009-3555.txt
- [Other]http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html
- [Other]http://ubuntu.com/usn/usn-923-1
- [Other]http://wiki.rpath.com/Advisories:rPSA-2009-0155
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg21426108
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg21432298
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg24006386
- [Other]http://www-01.ibm.com/support/docview.wss?uid=swg24025312
- [Other]http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only
- [Other]http://www.arubanetworks.com/support/alerts/aid-020810.txt
- [Other]http://www.betanews.com/article/1257452450
- [Other]http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml
- [Other]http://www.debian.org/security/2009/dsa-1934
- [Other]http://www.debian.org/security/2011/dsa-2141
- [Other]http://www.debian.org/security/2015/dsa-3253
- [Other]http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html
- [Other]http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html
- [Other]http://www.ietf.org/mail-archive/web/tls/current/msg03928.html
- [Other]http://www.ietf.org/mail-archive/web/tls/current/msg03948.html
- [Other]http://www.ingate.com/Relnote.php?ver=481
- [Other]http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995
- [Other]http://www.kb.cert.org/vuls/id/120541
- [Other]http://www.links.org/?p=780
- [Other]http://www.links.org/?p=786
- [Other]http://www.links.org/?p=789
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:076
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
- [Other]http://www.mandriva.com/security/advisories?name=MDVSA-2010:089
- [Other]http://www.mozilla.org/security/announce/2010/mfsa2010-22.html
- [Other]http://www.openoffice.org/security/cves/CVE-2009-3555.html
- [Other]http://www.openssl.org/news/secadv_20091111.txt
- [Other]http://www.openwall.com/lists/oss-security/2009/11/05/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/05/5
- [Other]http://www.openwall.com/lists/oss-security/2009/11/06/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/07/3
- [Other]http://www.openwall.com/lists/oss-security/2009/11/20/1
- [Other]http://www.openwall.com/lists/oss-security/2009/11/23/10
- [Other]http://www.opera.com/docs/changelogs/unix/1060/
- [Other]http://www.opera.com/support/search/view/944/
- [Other]http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
- [Other]http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- [Other]http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
- [Other]http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0119.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0130.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0155.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0165.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0167.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0337.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0338.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0339.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0768.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0770.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0786.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0807.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0865.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0986.html
- [Other]http://www.redhat.com/support/errata/RHSA-2010-0987.html
- [Other]http://www.redhat.com/support/errata/RHSA-2011-0880.html
- [Other]http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html
- [Other]http://www.securityfocus.com/archive/1/507952/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/508075/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/508130/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/515055/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/516397/100/0/threaded
- [Other]http://www.securityfocus.com/archive/1/522176
- [Patch]http://www.securityfocus.com/bid/36935
- [Other]http://www.securitytracker.com/id?1023163
- [Other]http://www.securitytracker.com/id?1023204
- [Other]http://www.securitytracker.com/id?1023205
- [Other]http://www.securitytracker.com/id?1023206
- [Other]http://www.securitytracker.com/id?1023207
- [Other]http://www.securitytracker.com/id?1023208
- [Other]http://www.securitytracker.com/id?1023209
- [Other]http://www.securitytracker.com/id?1023210
- [Other]http://www.securitytracker.com/id?1023211
- [Other]http://www.securitytracker.com/id?1023212
- [Other]http://www.securitytracker.com/id?1023213
- [Other]http://www.securitytracker.com/id?1023214
- [Other]http://www.securitytracker.com/id?1023215
- [Other]http://www.securitytracker.com/id?1023216
- [Other]http://www.securitytracker.com/id?1023217
- [Other]http://www.securitytracker.com/id?1023218
- [Other]http://www.securitytracker.com/id?1023219
- [Other]http://www.securitytracker.com/id?1023224
- [Other]http://www.securitytracker.com/id?1023243
- [Other]http://www.securitytracker.com/id?1023270
- [Other]http://www.securitytracker.com/id?1023271
- [Other]http://www.securitytracker.com/id?1023272
- [Other]http://www.securitytracker.com/id?1023273
- [Other]http://www.securitytracker.com/id?1023274
- [Other]http://www.securitytracker.com/id?1023275
- [Other]http://www.securitytracker.com/id?1023411
- [Other]http://www.securitytracker.com/id?1023426
- [Other]http://www.securitytracker.com/id?1023427
- [Other]http://www.securitytracker.com/id?1023428
- [Other]http://www.securitytracker.com/id?1024789
- [Other]http://www.tombom.co.uk/blog/?p=85
- [Other]http://www.ubuntu.com/usn/USN-1010-1
- [Other]http://www.ubuntu.com/usn/USN-927-1
- [Other]http://www.ubuntu.com/usn/USN-927-4
- [Other]http://www.ubuntu.com/usn/USN-927-5
- [Other]http://www.us-cert.gov/cas/techalerts/TA10-222A.html
- [Other]http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- [Other]http://www.vmware.com/security/advisories/VMSA-2010-0019.html
- [Other]http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- [Other]http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
- [Other]http://www.vupen.com/english/advisories/2009/3164
- [Other]http://www.vupen.com/english/advisories/2009/3165
- [Other]http://www.vupen.com/english/advisories/2009/3205
- [Other]http://www.vupen.com/english/advisories/2009/3220
- [Other]http://www.vupen.com/english/advisories/2009/3310
- [Other]http://www.vupen.com/english/advisories/2009/3313
- [Other]http://www.vupen.com/english/advisories/2009/3353
- [Other]http://www.vupen.com/english/advisories/2009/3354
- [Other]http://www.vupen.com/english/advisories/2009/3484
- [Other]http://www.vupen.com/english/advisories/2009/3521
- [Other]http://www.vupen.com/english/advisories/2009/3587
- [Other]http://www.vupen.com/english/advisories/2010/0086
- [Other]http://www.vupen.com/english/advisories/2010/0173
- [Other]http://www.vupen.com/english/advisories/2010/0748
- [Other]http://www.vupen.com/english/advisories/2010/0848
- [Other]http://www.vupen.com/english/advisories/2010/0916
- [Other]http://www.vupen.com/english/advisories/2010/0933
- [Other]http://www.vupen.com/english/advisories/2010/0982
- [Other]http://www.vupen.com/english/advisories/2010/0994
- [Other]http://www.vupen.com/english/advisories/2010/1054
- [Other]http://www.vupen.com/english/advisories/2010/1107
- [Other]http://www.vupen.com/english/advisories/2010/1191
- [Other]http://www.vupen.com/english/advisories/2010/1350
- [Other]http://www.vupen.com/english/advisories/2010/1639
- [Other]http://www.vupen.com/english/advisories/2010/1673
- [Other]http://www.vupen.com/english/advisories/2010/1793
- [Other]http://www.vupen.com/english/advisories/2010/2010
- [Other]http://www.vupen.com/english/advisories/2010/2745
- [Other]http://www.vupen.com/english/advisories/2010/3069
- [Other]http://www.vupen.com/english/advisories/2010/3086
- [Other]http://www.vupen.com/english/advisories/2010/3126
- [Other]http://www.vupen.com/english/advisories/2011/0032
- [Other]http://www.vupen.com/english/advisories/2011/0033
- [Other]http://www.vupen.com/english/advisories/2011/0086
- [Exploit reference]http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=526689
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=545755
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=533125
- [Patch]https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049
- [Other]https://exchange.xforce.ibmcloud.com/vulnerabilities/54158
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- [Other]https://kb.bluecoat.com/index?page=content&id=SA50
- [Other]https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E
- [Other]https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366
- [Other]https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535
- [Other]https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html
- [Other]https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html
- [Other]https://www.exploit-db.com/exploits/10579
Related CVEs
Same vendor
- CVE-2026-34905 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer (6.5 MEDIUM)
- CVE-2026-34031 — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer (6.5 MEDIUM)
- CVE-2026-33582 — Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer (6.5 MEDIUM)
- CVE-2026-25699 — Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer (6.1 MEDIUM)
- CVE-2026-25688 — Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer (6.1 MEDIUM)
Same CWE
- CVE-2026-53475 — A flaw was found in assisted-migration-agent (9.3 CRITICAL)
- CVE-2026-9758 — Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered tru... (7.3 HIGH)
- CVE-2026-41714 — Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(... (4.0 MEDIUM)
- CVE-2026-42769 — Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (... (5.3 MEDIUM)
- CVE-2026-50752 — A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a... (7.4 HIGH)