CVE-2015-2808

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

Published at
2015-04-01T02:00Z
3337 days ago
Modified
2020-11-23T19:47Z
1273 days ago
CWE-327
Problem type

References


URLType
www.blackhat.com
https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf
MISC
IV71888
http://www-01.ibm.com/support/docview.wss?uid=swg1IV71888
AIXAPAR
www-01.ibm.com
http://www-01.ibm.com/support/docview.wss?uid=swg21883640
CONFIRM
IV71892
http://www-01.ibm.com/support/docview.wss?uid=swg1IV71892
AIXAPAR
www.oracle.com
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
CONFIRM
SSRT102133
http://marc.info/?l=bugtraq&m=143817021313142&w=2
HP
HPSBGN03367
http://marc.info/?l=bugtraq&m=143817899717054&w=2
HP
HPSBMU03377
http://marc.info/?l=bugtraq&m=143741441012338&w=2
HP
SSRT102127
http://marc.info/?l=bugtraq&m=143818140118771&w=2
HP
www.oracle.com
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
CONFIRM
www.huawei.com
http://www.huawei.com/en/psirt/security-advisories/hw-454055
CONFIRM
h20566.www2.hpe.com
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988
CONFIRM
www.oracle.com
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
CONFIRM
91787
http://www.securityfocus.com/bid/91787
BID
h20566.www2.hpe.com
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347
CONFIRM
HPSBGN03399
http://marc.info/?l=bugtraq&m=144060576831314&w=2
HP
HPSBGN03402
http://marc.info/?l=bugtraq&m=144069189622016&w=2
HP
HPSBUX03512
http://marc.info/?l=bugtraq&m=144493176821532&w=2
HP
HPSBGN03407
http://marc.info/?l=bugtraq&m=144102017024820&w=2
HP
HPSBGN03354
http://marc.info/?l=bugtraq&m=143629696317098&w=2
HP
HPSBMU03345
http://marc.info/?l=bugtraq&m=144043644216842&w=2
HP
HPSBGN03414
http://marc.info/?l=bugtraq&m=144059660127919&w=2
HP
HPSBGN03415
http://marc.info/?l=bugtraq&m=144059703728085&w=2
HP
HPSBGN03403
http://marc.info/?l=bugtraq&m=144104565600964&w=2
HP
HPSBGN03338
http://marc.info/?l=bugtraq&m=143456209711959&w=2
HP
HPSBMU03401
http://marc.info/?l=bugtraq&m=144104533800819&w=2
HP
HPSBGN03405
http://marc.info/?l=bugtraq&m=144060606031437&w=2
HP
h20566.www2.hpe.com
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935
CONFIRM
h20566.www2.hpe.com
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888
CONFIRM
kc.mcafee.com
https://kc.mcafee.com/corporate/index?page=content&id=SB10163
CONFIRM
1032599
http://www.securitytracker.com/id/1032599
SECTRACK
kb.juniper.net
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727
CONFIRM
SUSE-SU-2015:2166
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
SUSE
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789
CONFIRM
GLSA-201512-10
https://security.gentoo.org/glsa/201512-10
GENTOO
www1.huawei.com
http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htm
CONFIRM
SUSE-SU-2015:2192
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
SUSE
SUSE-SU-2016:0113
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
SUSE
www-947.ibm.com
https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709
CONFIRM
1033769
http://www.securitytracker.com/id/1033769
SECTRACK
kb.juniper.net
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
CONFIRM
h20564.www2.hpe.com
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034
CONFIRM
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246
CONFIRM
1033737
http://www.securitytracker.com/id/1033737
SECTRACK
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256
CONFIRM
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119
CONFIRM
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190
CONFIRM
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140
CONFIRM
1033432
http://www.securitytracker.com/id/1033432
SECTRACK
1033431
http://www.securitytracker.com/id/1033431
SECTRACK
1033415
http://www.securitytracker.com/id/1033415
SECTRACK
1033386
http://www.securitytracker.com/id/1033386
SECTRACK
h20564.www2.hpe.com
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241
CONFIRM
USN-2706-1
http://www.ubuntu.com/usn/USN-2706-1
UBUNTU
USN-2696-1
http://www.ubuntu.com/usn/USN-2696-1
UBUNTU
DSA-3339
http://www.debian.org/security/2015/dsa-3339
DEBIAN
RHSA-2015:1526
http://rhn.redhat.com/errata/RHSA-2015-1526.html
REDHAT
SUSE-SU-2015:1320
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html
SUSE
SUSE-SU-2015:1319
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html
SUSE
openSUSE-SU-2015:1289
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html
SUSE
openSUSE-SU-2015:1288
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html
SUSE
www-304.ibm.com
http://www-304.ibm.com/support/docview.wss?uid=swg21960769
CONFIRM
www-304.ibm.com
http://www-304.ibm.com/support/docview.wss?uid=swg21960015
CONFIRM
www-304.ibm.com
http://www-304.ibm.com/support/docview.wss?uid=swg21903565
CONFIRM
1032868
http://www.securitytracker.com/id/1032868
SECTRACK
1032858
http://www.securitytracker.com/id/1032858
SECTRACK
1032788
http://www.securitytracker.com/id/1032788
SECTRACK
1032734
http://www.securitytracker.com/id/1032734
SECTRACK
1032708
http://www.securitytracker.com/id/1032708
SECTRACK
1032707
http://www.securitytracker.com/id/1032707
SECTRACK
RHSA-2015:1091
http://rhn.redhat.com/errata/RHSA-2015-1091.html
REDHAT
RHSA-2015:1021
http://rhn.redhat.com/errata/RHSA-2015-1021.html
REDHAT
RHSA-2015:1020
http://rhn.redhat.com/errata/RHSA-2015-1020.html
REDHAT
RHSA-2015:1007
http://rhn.redhat.com/errata/RHSA-2015-1007.html
REDHAT
RHSA-2015:1006
http://rhn.redhat.com/errata/RHSA-2015-1006.html
REDHAT
SUSE-SU-2015:1161
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html
SUSE
SUSE-SU-2015:1138
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html
SUSE
SUSE-SU-2015:1086
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html
SUSE
SUSE-SU-2015:1085
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html
SUSE
SUSE-SU-2015:1073
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html
SUSE
73684
http://www.securityfocus.com/bid/73684
BID
kb.juniper.net
https://kb.juniper.net/JSA10783
CONFIRM
1036222
http://www.securitytracker.com/id/1036222
SECTRACK
h20566.www2.hpe.com
https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380
CONFIRM
h20566.www2.hpe.com
https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650
CONFIRM
1033072
http://www.securitytracker.com/id/1033072
SECTRACK
1033071
http://www.securitytracker.com/id/1033071
SECTRACK
1032990
http://www.securitytracker.com/id/1032990
SECTRACK
1032910
http://www.securitytracker.com/id/1032910
SECTRACK
1032600
http://www.securitytracker.com/id/1032600
SECTRACK
www.oracle.com
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
CONFIRM
DSA-3316
http://www.debian.org/security/2015/dsa-3316
DEBIAN
SSRT102073
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04687922
HP
RHSA-2015:1243
http://rhn.redhat.com/errata/RHSA-2015-1243.html
REDHAT
RHSA-2015:1242
http://rhn.redhat.com/errata/RHSA-2015-1242.html
REDHAT
RHSA-2015:1241
http://rhn.redhat.com/errata/RHSA-2015-1241.html
REDHAT
RHSA-2015:1230
http://rhn.redhat.com/errata/RHSA-2015-1230.html
REDHAT
RHSA-2015:1229
http://rhn.redhat.com/errata/RHSA-2015-1229.html
REDHAT
RHSA-2015:1228
http://rhn.redhat.com/errata/RHSA-2015-1228.html
REDHAT
www.oracle.com
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
CONFIRM

GET https://vulnerabilitydata.com/api/details/CVE-2015-2808

{
	"id": "CVE-2015-2808",
	"published_date": "2015-04-01T02:00Z",
	"last_modified_date": "2020-11-23T19:47Z",
	"assigner": "cve@mitre.org",
	"description": "The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the \"Bar Mitzvah\" issue.",
	"references": [
		{
			"url": "https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf",
			"name": "https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf",
			"refsource": "MISC",
			"tags": [
				"Technical Description",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV71888",
			"name": "IV71888",
			"refsource": "AIXAPAR",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21883640",
			"name": "http://www-01.ibm.com/support/docview.wss?uid=swg21883640",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV71892",
			"name": "IV71892",
			"refsource": "AIXAPAR",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html",
			"name": "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143817021313142&w=2",
			"name": "SSRT102133",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143817899717054&w=2",
			"name": "HPSBGN03367",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143741441012338&w=2",
			"name": "HPSBMU03377",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143818140118771&w=2",
			"name": "SSRT102127",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
			"name": "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.huawei.com/en/psirt/security-advisories/hw-454055",
			"name": "http://www.huawei.com/en/psirt/security-advisories/hw-454055",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988",
			"name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
			"name": "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securityfocus.com/bid/91787",
			"name": "91787",
			"refsource": "BID",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347",
			"name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144060576831314&w=2",
			"name": "HPSBGN03399",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144069189622016&w=2",
			"name": "HPSBGN03402",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144493176821532&w=2",
			"name": "HPSBUX03512",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144102017024820&w=2",
			"name": "HPSBGN03407",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143629696317098&w=2",
			"name": "HPSBGN03354",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144043644216842&w=2",
			"name": "HPSBMU03345",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144059660127919&w=2",
			"name": "HPSBGN03414",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144059703728085&w=2",
			"name": "HPSBGN03415",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144104565600964&w=2",
			"name": "HPSBGN03403",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=143456209711959&w=2",
			"name": "HPSBGN03338",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144104533800819&w=2",
			"name": "HPSBMU03401",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://marc.info/?l=bugtraq&m=144060606031437&w=2",
			"name": "HPSBGN03405",
			"refsource": "HP",
			"tags": [
				"Issue Tracking",
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935",
			"name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888",
			"name": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10163",
			"name": "https://kc.mcafee.com/corporate/index?page=content&id=SB10163",
			"refsource": "CONFIRM",
			"tags": [
				"Broken Link"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032599",
			"name": "1032599",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727",
			"name": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html",
			"name": "SUSE-SU-2015:2166",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://security.gentoo.org/glsa/201512-10",
			"name": "GLSA-201512-10",
			"refsource": "GENTOO",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htm",
			"name": "http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htm",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html",
			"name": "SUSE-SU-2015:2192",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html",
			"name": "SUSE-SU-2016:0113",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709",
			"name": "https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033769",
			"name": "1033769",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
			"name": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034",
			"name": "http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033737",
			"name": "1033737",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033432",
			"name": "1033432",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033431",
			"name": "1033431",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033415",
			"name": "1033415",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033386",
			"name": "1033386",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241",
			"name": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.ubuntu.com/usn/USN-2706-1",
			"name": "USN-2706-1",
			"refsource": "UBUNTU",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.ubuntu.com/usn/USN-2696-1",
			"name": "USN-2696-1",
			"refsource": "UBUNTU",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.debian.org/security/2015/dsa-3339",
			"name": "DSA-3339",
			"refsource": "DEBIAN",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1526.html",
			"name": "RHSA-2015:1526",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html",
			"name": "SUSE-SU-2015:1320",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html",
			"name": "SUSE-SU-2015:1319",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html",
			"name": "openSUSE-SU-2015:1289",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html",
			"name": "openSUSE-SU-2015:1288",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-304.ibm.com/support/docview.wss?uid=swg21960769",
			"name": "http://www-304.ibm.com/support/docview.wss?uid=swg21960769",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-304.ibm.com/support/docview.wss?uid=swg21960015",
			"name": "http://www-304.ibm.com/support/docview.wss?uid=swg21960015",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www-304.ibm.com/support/docview.wss?uid=swg21903565",
			"name": "http://www-304.ibm.com/support/docview.wss?uid=swg21903565",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032868",
			"name": "1032868",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032858",
			"name": "1032858",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032788",
			"name": "1032788",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032734",
			"name": "1032734",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032708",
			"name": "1032708",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032707",
			"name": "1032707",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1091.html",
			"name": "RHSA-2015:1091",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1021.html",
			"name": "RHSA-2015:1021",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1020.html",
			"name": "RHSA-2015:1020",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1007.html",
			"name": "RHSA-2015:1007",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1006.html",
			"name": "RHSA-2015:1006",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html",
			"name": "SUSE-SU-2015:1161",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html",
			"name": "SUSE-SU-2015:1138",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html",
			"name": "SUSE-SU-2015:1086",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html",
			"name": "SUSE-SU-2015:1085",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html",
			"name": "SUSE-SU-2015:1073",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securityfocus.com/bid/73684",
			"name": "73684",
			"refsource": "BID",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://kb.juniper.net/JSA10783",
			"name": "https://kb.juniper.net/JSA10783",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1036222",
			"name": "1036222",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380",
			"name": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650",
			"name": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033072",
			"name": "1033072",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1033071",
			"name": "1033071",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032990",
			"name": "1032990",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032910",
			"name": "1032910",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.securitytracker.com/id/1032600",
			"name": "1032600",
			"refsource": "SECTRACK",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
			"name": "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
			"refsource": "CONFIRM",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.debian.org/security/2015/dsa-3316",
			"name": "DSA-3316",
			"refsource": "DEBIAN",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04687922",
			"name": "SSRT102073",
			"refsource": "HP",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1243.html",
			"name": "RHSA-2015:1243",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1242.html",
			"name": "RHSA-2015:1242",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1241.html",
			"name": "RHSA-2015:1241",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1230.html",
			"name": "RHSA-2015:1230",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1229.html",
			"name": "RHSA-2015:1229",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2015-1228.html",
			"name": "RHSA-2015:1228",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
			"name": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
			"refsource": "CONFIRM",
			"tags": [
				"Patch",
				"Third Party Advisory"
			]
		}
	],
	"impact": {
		"baseMetricV2": {
			"cvssV2": {
				"version": "2.0",
				"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
				"accessVector": "NETWORK",
				"accessComplexity": "LOW",
				"authentication": "NONE",
				"confidentialityImpact": "PARTIAL",
				"integrityImpact": "NONE",
				"availabilityImpact": "NONE",
				"baseScore": 5
			},
			"severity": "MEDIUM",
			"exploitabilityScore": 10,
			"impactScore": 2.9,
			"acInsufInfo": false,
			"obtainAllPrivilege": false,
			"obtainUserPrivilege": false,
			"obtainOtherPrivilege": false,
			"userInteractionRequired": false
		}
	},
	"problem_type": "CWE-327"
}