{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-11-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a \"plaintext injection\" attack, aka the \"Project Mogul\" issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2020-02-13T16:08:08.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"1023427","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023427"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100081611"},{"name":"62210","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/62210"},{"name":"37640","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37640"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.arubanetworks.com/support/alerts/aid-020810.txt"},{"name":"ADV-2010-0916","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0916"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100114327"},{"name":"RHSA-2010:0167","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0167.html"},{"name":"ADV-2010-2010","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2010"},{"name":"FEDORA-2009-12750","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html"},{"name":"ADV-2010-0086","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0086"},{"name":"ADV-2010-1673","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1673"},{"name":"[tls] 20091104 TLS renegotiation issue","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03948.html"},{"name":"37656","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37656"},{"name":"RHSA-2010:0865","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0865.html"},{"name":"39628","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39628"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"},{"name":"42724","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42724"},{"name":"ADV-2009-3310","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3310"},{"name":"ADV-2009-3205","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3205"},{"tags":["x_refsource_CONFIRM"],"url":"http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during"},{"name":"39461","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39461"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100114315"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c"},{"name":"GLSA-201406-32","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201406-32.xml"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ingate.com/Relnote.php?ver=481"},{"name":"1023204","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023204"},{"name":"40866","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40866"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"TA10-222A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-222A.html"},{"name":"1023211","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023211"},{"name":"SSRT090249","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39317"},{"name":"1023212","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023212"},{"name":"SUSE-SA:2010:061","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html"},{"name":"39127","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39127"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40545"},{"name":"ADV-2010-3069","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/3069"},{"name":"[4.5] 010: SECURITY FIX: November 26, 2009","tags":["vendor-advisory","x_refsource_OPENBSD"],"url":"http://openbsd.org/errata45.html#010_openssl"},{"name":"1023210","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023210"},{"name":"1023270","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023270"},{"name":"40070","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40070"},{"name":"1023273","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023273"},{"tags":["x_refsource_CONFIRM"],"url":"http://kbase.redhat.com/faq/docs/DOC-20491"},{"name":"USN-927-5","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-927-5"},{"name":"PM12247","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247"},{"name":"SUSE-SU-2011:0847","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html"},{"name":"MDVSA-2010:089","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:089"},{"name":"RHSA-2010:0770","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0770.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openssl.org/news/secadv_20091111.txt"},{"name":"1023275","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023275"},{"name":"DSA-3253","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3253"},{"name":"ADV-2009-3484","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3484"},{"name":"1023207","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023207"},{"name":"37859","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37859"},{"name":"SSRT101846","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"1021752","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1"},{"name":"FEDORA-2010-6131","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html"},{"name":"ADV-2010-0848","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0848"},{"name":"[oss-security] 20091107 Re: [TLS] CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/07/3"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39819"},{"name":"IC68055","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055"},{"tags":["x_refsource_MISC"],"url":"http://www.links.org/?p=786"},{"name":"60521","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/60521"},{"name":"[oss-security] 20091123 Re: CVEs for nginx","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/23/10"},{"name":"VU#120541","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/120541"},{"name":"1023217","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023217"},{"name":"RHSA-2010:0768","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0768.html"},{"name":"ADV-2009-3353","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3353"},{"name":"FEDORA-2010-5357","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html"},{"name":"39136","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39136"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openoffice.org/security/cves/CVE-2009-3555.html"},{"name":"ADV-2011-0032","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0032"},{"name":"1023148","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023148"},{"name":"openSUSE-SU-2011:0845","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html"},{"name":"36935","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36935"},{"tags":["x_refsource_MISC"],"url":"http://www.tombom.co.uk/blog/?p=85"},{"name":"SSRT090208","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2"},{"name":"ADV-2010-1107","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1107"},{"name":"1023218","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023218"},{"name":"ADV-2010-1350","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1350"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"42379","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42379"},{"name":"FEDORA-2009-12775","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html"},{"name":"20091109 Transport Layer Security Renegotiation Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml"},{"name":"IC67848","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848"},{"name":"1023213","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023213"},{"name":"FEDORA-2010-16240","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"oval:org.mitre.oval:def:11617","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617"},{"tags":["x_refsource_MISC"],"url":"http://extendedsubset.com/?p=8"},{"name":"37292","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37292"},{"name":"SSRT100817","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/522176"},{"name":"tls-renegotiation-weak-security(54158)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54158"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"39278","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39278"},{"name":"1023205","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023205"},{"name":"RHSA-2010:0130","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0130.html"},{"name":"HPSBUX02482","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686"},{"name":"HPSBHF03293","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4004"},{"name":"1023215","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023215"},{"name":"USN-1010-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1010-1"},{"name":"1023206","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023206"},{"name":"SUSE-SR:2010:011","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888"},{"name":"GLSA-200912-01","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200912-01.xml"},{"name":"SSRT090180","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2"},{"name":"ADV-2009-3313","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3313"},{"name":"274990","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1"},{"name":"1023208","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023208"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43308"},{"name":"1023214","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023214"},{"name":"SUSE-SA:2009:057","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html"},{"name":"38781","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38781"},{"name":"HPSBOV02762","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2"},{"name":"HPSBMA02534","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2"},{"name":"DSA-1934","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1934"},{"name":"FEDORA-2009-12782","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html"},{"name":"oval:org.mitre.oval:def:7478","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478"},{"name":"1023271","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023271"},{"name":"APPLE-SA-2010-01-19-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html"},{"name":"[cryptography] 20091105 OpenSSL 0.9.8l released","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=cryptography&m=125752275331877&w=2"},{"name":"42467","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42467"},{"name":"20091130 TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/508130/100/0/threaded"},{"name":"oval:org.mitre.oval:def:7315","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315"},{"name":"1023224","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023224"},{"name":"SUSE-SR:2010:013","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html"},{"name":"USN-927-4","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-927-4"},{"name":"41490","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41490"},{"name":"20091124 rPSA-2009-0155-1 httpd mod_ssl","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/508075/100/0/threaded"},{"name":"1023243","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023243"},{"tags":["x_refsource_MISC"],"url":"http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html"},{"name":"37504","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37504"},{"name":"1023219","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023219"},{"tags":["x_refsource_CONFIRM"],"url":"http://sysoev.ru/nginx/patch.cve-2009-3555.txt"},{"tags":["x_refsource_MISC"],"url":"http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html"},{"name":"1023163","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023163"},{"name":"HPSBHF02706","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2"},{"name":"ADV-2009-3521","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3521"},{"name":"oval:org.mitre.oval:def:7973","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973"},{"name":"HPSBMA02568","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=533125"},{"name":"oval:org.mitre.oval:def:10088","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088"},{"name":"44183","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44183"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES"},{"name":"42808","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42808"},{"name":"39500","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39500"},{"name":"oval:org.mitre.oval:def:11578","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"ADV-2009-3220","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3220"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"RHSA-2010:0165","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0165.html"},{"name":"20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/515055/100/0/threaded"},{"name":"RHSA-2010:0987","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0987.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=545755"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21426108"},{"tags":["x_refsource_MISC"],"url":"http://blogs.iss.net/archive/sslmitmiscsrf.html"},{"name":"1023411","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023411"},{"name":"RHSA-2010:0339","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html"},{"name":"RHSA-2010:0986","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0986.html"},{"name":"ADV-2009-3164","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3164"},{"name":"37383","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37383"},{"name":"FEDORA-2009-12229","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html"},{"name":"44954","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/44954"},{"name":"[tls] 20091104 MITM attack on delayed TLS-client auth through renegotiation","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03928.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100070150"},{"name":"40747","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40747"},{"name":"HPSBUX02498","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2"},{"name":"HPSBMU02759","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/522176"},{"name":"39292","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39292"},{"name":"42816","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42816"},{"name":"IC68054","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054"},{"name":"273029","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1"},{"name":"FEDORA-2009-12604","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21432298"},{"tags":["x_refsource_MISC"],"url":"http://extendedsubset.com/Renegotiating_TLS.pdf"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24025312"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24006386"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4170"},{"name":"20091118 TLS / SSLv3 vulnerability explained (DRAFT)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/507952/100/0/threaded"},{"name":"1023209","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023209"},{"name":"PM00675","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"HPSBOV02683","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2"},{"name":"48577","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/48577"},{"name":"SSA:2009-320-01","tags":["vendor-advisory","x_refsource_SLACKWARE"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446"},{"tags":["x_refsource_MISC"],"url":"http://www.links.org/?p=789"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.opera.com/docs/changelogs/unix/1060/"},{"tags":["x_refsource_MISC"],"url":"http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html"},{"name":"RHSA-2011:0880","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0880.html"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html"},{"name":"[oss-security] 20091107 Re: CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/06/3"},{"name":"FEDORA-2009-12305","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.rpath.com/Advisories:rPSA-2009-0155"},{"name":"SUSE-SR:2010:012","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.citrix.com/article/CTX123359"},{"name":"37501","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37501"},{"name":"MDVSA-2010:076","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:076"},{"name":"HPSBUX02517","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2"},{"name":"ADV-2009-3587","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3587"},{"name":"39632","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39632"},{"name":"SSRT090264","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2"},{"name":"38687","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38687"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=526689"},{"name":"MS10-049","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049"},{"name":"ADV-2010-0982","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0982"},{"name":"SSRT100825","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2"},{"name":"37399","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37399"},{"name":"USN-927-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-927-1"},{"name":"1023272","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023272"},{"name":"FEDORA-2009-12606","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html"},{"name":"ADV-2010-3126","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/3126"},{"name":"37320","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37320"},{"name":"ADV-2009-3165","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3165"},{"name":"ADV-2010-1639","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1639"},{"name":"38020","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38020"},{"name":"USN-923-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-923-1"},{"name":"39243","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39243"},{"name":"oval:org.mitre.oval:def:8366","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366"},{"name":"37453","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37453"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html"},{"name":"ADV-2010-0933","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0933"},{"name":"SSRT100219","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"41972","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41972"},{"name":"ADV-2010-3086","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/3086"},{"name":"DSA-2141","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2011/dsa-2141"},{"name":"1024789","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024789"},{"name":"RHSA-2010:0155","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0155.html"},{"tags":["x_refsource_MISC"],"url":"http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html"},{"name":"ADV-2011-0033","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0033"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"1023216","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023216"},{"name":"41480","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41480"},{"name":"ADV-2011-0086","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0086"},{"name":"41818","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41818"},{"name":"37604","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37604"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.opera.com/support/search/view/944/"},{"name":"[announce] 20091107 CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2"},{"name":"SUSE-SR:2010:024","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"},{"name":"TA10-287A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-287A.html"},{"tags":["x_refsource_MISC"],"url":"http://www.links.org/?p=780"},{"name":"RHSA-2010:0119","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0119.html"},{"name":"38056","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38056"},{"name":"ADV-2010-0748","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0748"},{"name":"37675","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37675"},{"name":"oval:org.mitre.oval:def:8535","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100058","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2010-0019.html"},{"name":"RHSA-2010:0786","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0786.html"},{"tags":["x_refsource_MISC"],"url":"https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt"},{"name":"38003","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38003"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4171"},{"name":"1023428","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023428"},{"name":"SSRT100613","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2"},{"name":"[oss-security] 20091120 CVEs for nginx","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/20/1"},{"name":"ADV-2009-3354","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3354"},{"name":"1023274","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023274"},{"name":"FEDORA-2009-12968","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html"},{"name":"39242","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39242"},{"tags":["x_refsource_CONFIRM"],"url":"https://kb.bluecoat.com/index?page=content&id=SA50"},{"name":"38241","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38241"},{"name":"42377","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42377"},{"name":"GLSA-201203-22","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201203-22.xml"},{"name":"[oss-security] 20091105 CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/05/3"},{"name":"SUSE-SR:2010:019","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"},{"name":"60972","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/60972"},{"name":"1023426","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023426"},{"name":"38484","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38484"},{"name":"MDVSA-2010:084","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084"},{"tags":["x_refsource_MISC"],"url":"http://www.betanews.com/article/1257452450"},{"name":"1021653","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-22.html"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"[4.6] 004: SECURITY FIX: November 26, 2009","tags":["vendor-advisory","x_refsource_OPENBSD"],"url":"http://openbsd.org/errata46.html#004_openssl"},{"name":"41967","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41967"},{"name":"RHSA-2010:0807","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0807.html"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1191"},{"name":"20091111 Re: SSL/TLS MiTM PoC","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2009/Nov/139"},{"tags":["x_refsource_MISC"],"url":"https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html"},{"name":"[oss-security] 20091105 Re: CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/11/05/5"},{"name":"39713","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39713"},{"name":"42733","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42733"},{"name":"37291","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37291"},{"name":"FEDORA-2010-16312","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html"},{"name":"FEDORA-2010-5942","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html"},{"name":"ADV-2010-2745","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2745"},{"name":"273350","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1"},{"name":"ADV-2010-0994","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0994"},{"name":"ADV-2010-0173","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0173"},{"name":"ADV-2010-1054","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1054"},{"name":"65202","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/65202"},{"name":"HPSBGN02562","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041"},{"name":"FEDORA-2010-16294","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html"},{"name":"[gnutls-devel] 20091105 Re: TLS renegotiation MITM","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html"},{"name":"20131121 ESA-2013-077: RSA Data Protection Manager Appliance Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html"},{"tags":["x_refsource_MISC"],"url":"http://clicky.me/tlsvuln"},{"name":"42811","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42811"},{"name":"[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20200213 svn commit: r1873980 [31/34] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-07T06:31:10.430Z"},"title":"CVE Program Container","references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"1023427","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023427"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100081611"},{"name":"62210","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/62210"},{"name":"37640","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37640"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.arubanetworks.com/support/alerts/aid-020810.txt"},{"name":"ADV-2010-0916","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0916"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100114327"},{"name":"RHSA-2010:0167","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0167.html"},{"name":"ADV-2010-2010","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2010"},{"name":"FEDORA-2009-12750","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html"},{"name":"ADV-2010-0086","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0086"},{"name":"ADV-2010-1673","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1673"},{"name":"[tls] 20091104 TLS renegotiation issue","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03948.html"},{"name":"37656","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37656"},{"name":"RHSA-2010:0865","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0865.html"},{"name":"39628","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39628"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"},{"name":"42724","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42724"},{"name":"ADV-2009-3310","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3310"},{"name":"ADV-2009-3205","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3205"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during"},{"name":"39461","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39461"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100114315"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c"},{"name":"GLSA-201406-32","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201406-32.xml"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ingate.com/Relnote.php?ver=481"},{"name":"1023204","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023204"},{"name":"40866","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40866"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"TA10-222A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-222A.html"},{"name":"1023211","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023211"},{"name":"SSRT090249","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39317"},{"name":"1023212","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023212"},{"name":"SUSE-SA:2010:061","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html"},{"name":"39127","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39127"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40545"},{"name":"ADV-2010-3069","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/3069"},{"name":"[4.5] 010: SECURITY FIX: November 26, 2009","tags":["vendor-advisory","x_refsource_OPENBSD","x_transferred"],"url":"http://openbsd.org/errata45.html#010_openssl"},{"name":"1023210","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023210"},{"name":"1023270","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023270"},{"name":"40070","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40070"},{"name":"1023273","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023273"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kbase.redhat.com/faq/docs/DOC-20491"},{"name":"USN-927-5","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-927-5"},{"name":"PM12247","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247"},{"name":"SUSE-SU-2011:0847","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html"},{"name":"MDVSA-2010:089","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:089"},{"name":"RHSA-2010:0770","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0770.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openssl.org/news/secadv_20091111.txt"},{"name":"1023275","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023275"},{"name":"DSA-3253","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3253"},{"name":"ADV-2009-3484","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3484"},{"name":"1023207","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023207"},{"name":"37859","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37859"},{"name":"SSRT101846","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"1021752","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1"},{"name":"FEDORA-2010-6131","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html"},{"name":"ADV-2010-0848","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0848"},{"name":"[oss-security] 20091107 Re: [TLS] CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/07/3"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39819"},{"name":"IC68055","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.links.org/?p=786"},{"name":"60521","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/60521"},{"name":"[oss-security] 20091123 Re: CVEs for nginx","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/23/10"},{"name":"VU#120541","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/120541"},{"name":"1023217","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023217"},{"name":"RHSA-2010:0768","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0768.html"},{"name":"ADV-2009-3353","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3353"},{"name":"FEDORA-2010-5357","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html"},{"name":"39136","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39136"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openoffice.org/security/cves/CVE-2009-3555.html"},{"name":"ADV-2011-0032","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0032"},{"name":"1023148","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023148"},{"name":"openSUSE-SU-2011:0845","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html"},{"name":"36935","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36935"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.tombom.co.uk/blog/?p=85"},{"name":"SSRT090208","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2"},{"name":"ADV-2010-1107","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1107"},{"name":"1023218","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023218"},{"name":"ADV-2010-1350","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1350"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"42379","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42379"},{"name":"FEDORA-2009-12775","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html"},{"name":"20091109 Transport Layer Security Renegotiation Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml"},{"name":"IC67848","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848"},{"name":"1023213","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023213"},{"name":"FEDORA-2010-16240","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"oval:org.mitre.oval:def:11617","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://extendedsubset.com/?p=8"},{"name":"37292","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37292"},{"name":"SSRT100817","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/522176"},{"name":"tls-renegotiation-weak-security(54158)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54158"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"39278","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39278"},{"name":"1023205","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023205"},{"name":"RHSA-2010:0130","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0130.html"},{"name":"HPSBUX02482","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686"},{"name":"HPSBHF03293","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4004"},{"name":"1023215","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023215"},{"name":"USN-1010-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1010-1"},{"name":"1023206","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023206"},{"name":"SUSE-SR:2010:011","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888"},{"name":"GLSA-200912-01","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200912-01.xml"},{"name":"SSRT090180","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2"},{"name":"ADV-2009-3313","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3313"},{"name":"274990","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1"},{"name":"1023208","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023208"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43308"},{"name":"1023214","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023214"},{"name":"SUSE-SA:2009:057","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html"},{"name":"38781","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38781"},{"name":"HPSBOV02762","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2"},{"name":"HPSBMA02534","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2"},{"name":"DSA-1934","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1934"},{"name":"FEDORA-2009-12782","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html"},{"name":"oval:org.mitre.oval:def:7478","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478"},{"name":"1023271","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023271"},{"name":"APPLE-SA-2010-01-19-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html"},{"name":"[cryptography] 20091105 OpenSSL 0.9.8l released","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=cryptography&m=125752275331877&w=2"},{"name":"42467","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42467"},{"name":"20091130 TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/508130/100/0/threaded"},{"name":"oval:org.mitre.oval:def:7315","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315"},{"name":"1023224","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023224"},{"name":"SUSE-SR:2010:013","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html"},{"name":"USN-927-4","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-927-4"},{"name":"41490","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41490"},{"name":"20091124 rPSA-2009-0155-1 httpd mod_ssl","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/508075/100/0/threaded"},{"name":"1023243","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023243"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html"},{"name":"37504","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37504"},{"name":"1023219","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023219"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sysoev.ru/nginx/patch.cve-2009-3555.txt"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html"},{"name":"1023163","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023163"},{"name":"HPSBHF02706","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2"},{"name":"ADV-2009-3521","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3521"},{"name":"oval:org.mitre.oval:def:7973","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973"},{"name":"HPSBMA02568","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=533125"},{"name":"oval:org.mitre.oval:def:10088","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088"},{"name":"44183","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44183"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES"},{"name":"42808","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42808"},{"name":"39500","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39500"},{"name":"oval:org.mitre.oval:def:11578","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"ADV-2009-3220","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3220"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"RHSA-2010:0165","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0165.html"},{"name":"20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/515055/100/0/threaded"},{"name":"RHSA-2010:0987","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0987.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=545755"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21426108"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.iss.net/archive/sslmitmiscsrf.html"},{"name":"1023411","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023411"},{"name":"RHSA-2010:0339","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html"},{"name":"RHSA-2010:0986","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0986.html"},{"name":"ADV-2009-3164","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3164"},{"name":"37383","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37383"},{"name":"FEDORA-2009-12229","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html"},{"name":"44954","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/44954"},{"name":"[tls] 20091104 MITM attack on delayed TLS-client auth through renegotiation","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03928.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100070150"},{"name":"40747","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40747"},{"name":"HPSBUX02498","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2"},{"name":"HPSBMU02759","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/522176"},{"name":"39292","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39292"},{"name":"42816","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42816"},{"name":"IC68054","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054"},{"name":"273029","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1"},{"name":"FEDORA-2009-12604","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21432298"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://extendedsubset.com/Renegotiating_TLS.pdf"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24025312"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24006386"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4170"},{"name":"20091118 TLS / SSLv3 vulnerability explained (DRAFT)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/507952/100/0/threaded"},{"name":"1023209","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023209"},{"name":"PM00675","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"HPSBOV02683","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2"},{"name":"48577","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/48577"},{"name":"SSA:2009-320-01","tags":["vendor-advisory","x_refsource_SLACKWARE","x_transferred"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.links.org/?p=789"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.opera.com/docs/changelogs/unix/1060/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html"},{"name":"RHSA-2011:0880","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0880.html"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html"},{"name":"[oss-security] 20091107 Re: CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/06/3"},{"name":"FEDORA-2009-12305","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.rpath.com/Advisories:rPSA-2009-0155"},{"name":"SUSE-SR:2010:012","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.citrix.com/article/CTX123359"},{"name":"37501","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37501"},{"name":"MDVSA-2010:076","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:076"},{"name":"HPSBUX02517","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2"},{"name":"ADV-2009-3587","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3587"},{"name":"39632","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39632"},{"name":"SSRT090264","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2"},{"name":"38687","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38687"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=526689"},{"name":"MS10-049","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049"},{"name":"ADV-2010-0982","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0982"},{"name":"SSRT100825","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2"},{"name":"37399","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37399"},{"name":"USN-927-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-927-1"},{"name":"1023272","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023272"},{"name":"FEDORA-2009-12606","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html"},{"name":"ADV-2010-3126","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/3126"},{"name":"37320","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37320"},{"name":"ADV-2009-3165","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3165"},{"name":"ADV-2010-1639","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1639"},{"name":"38020","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38020"},{"name":"USN-923-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-923-1"},{"name":"39243","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39243"},{"name":"oval:org.mitre.oval:def:8366","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366"},{"name":"37453","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37453"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html"},{"name":"ADV-2010-0933","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0933"},{"name":"SSRT100219","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"41972","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41972"},{"name":"ADV-2010-3086","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/3086"},{"name":"DSA-2141","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2011/dsa-2141"},{"name":"1024789","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024789"},{"name":"RHSA-2010:0155","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0155.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html"},{"name":"ADV-2011-0033","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0033"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"1023216","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023216"},{"name":"41480","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41480"},{"name":"ADV-2011-0086","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0086"},{"name":"41818","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41818"},{"name":"37604","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37604"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.opera.com/support/search/view/944/"},{"name":"[announce] 20091107 CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2"},{"name":"SUSE-SR:2010:024","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"},{"name":"TA10-287A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-287A.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.links.org/?p=780"},{"name":"RHSA-2010:0119","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0119.html"},{"name":"38056","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38056"},{"name":"ADV-2010-0748","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0748"},{"name":"37675","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37675"},{"name":"oval:org.mitre.oval:def:8535","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100058","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2010-0019.html"},{"name":"RHSA-2010:0786","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0786.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt"},{"name":"38003","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38003"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4171"},{"name":"1023428","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023428"},{"name":"SSRT100613","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2"},{"name":"[oss-security] 20091120 CVEs for nginx","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/20/1"},{"name":"ADV-2009-3354","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3354"},{"name":"1023274","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023274"},{"name":"FEDORA-2009-12968","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html"},{"name":"39242","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39242"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kb.bluecoat.com/index?page=content&id=SA50"},{"name":"38241","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38241"},{"name":"42377","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42377"},{"name":"GLSA-201203-22","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201203-22.xml"},{"name":"[oss-security] 20091105 CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/05/3"},{"name":"SUSE-SR:2010:019","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"},{"name":"60972","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/60972"},{"name":"1023426","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023426"},{"name":"38484","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38484"},{"name":"MDVSA-2010:084","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.betanews.com/article/1257452450"},{"name":"1021653","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-22.html"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"[4.6] 004: SECURITY FIX: November 26, 2009","tags":["vendor-advisory","x_refsource_OPENBSD","x_transferred"],"url":"http://openbsd.org/errata46.html#004_openssl"},{"name":"41967","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41967"},{"name":"RHSA-2010:0807","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0807.html"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1191"},{"name":"20091111 Re: SSL/TLS MiTM PoC","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2009/Nov/139"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html"},{"name":"[oss-security] 20091105 Re: CVE-2009-3555 for TLS renegotiation MITM attacks","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/11/05/5"},{"name":"39713","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39713"},{"name":"42733","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42733"},{"name":"37291","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37291"},{"name":"FEDORA-2010-16312","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html"},{"name":"FEDORA-2010-5942","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html"},{"name":"ADV-2010-2745","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2745"},{"name":"273350","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1"},{"name":"ADV-2010-0994","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0994"},{"name":"ADV-2010-0173","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0173"},{"name":"ADV-2010-1054","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1054"},{"name":"65202","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/65202"},{"name":"HPSBGN02562","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041"},{"name":"FEDORA-2010-16294","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html"},{"name":"[gnutls-devel] 20091105 Re: TLS renegotiation MITM","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html"},{"name":"20131121 ESA-2013-077: RSA Data Protection Manager Appliance Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://clicky.me/tlsvuln"},{"name":"42811","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42811"},{"name":"[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20200213 svn commit: r1873980 [31/34] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E"}]}]},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-3555","datePublished":"2009-11-09T17:00:00.000Z","dateReserved":"2009-10-05T00:00:00.000Z","dateUpdated":"2024-08-07T06:31:10.430Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}