Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3616
Description:nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
Test IDs: 1.3.6.1.4.1.25623.1.0.703029   1.3.6.1.4.1.25623.1.0.841974   1.3.6.1.4.1.25623.1.0.868376   1.3.6.1.4.1.25623.1.0.868378   1.3.6.1.4.1.25623.1.0.120181   1.3.6.1.4.1.25623.1.0.121345   1.3.6.1.4.1.25623.1.0.150665  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3616
Debian Security Information: DSA-3029 (Google Search)
http://www.debian.org/security/2014/dsa-3029
http://mailman.nginx.org/pipermail/nginx-announce/2014/000147.html




© 1998-2024 E-Soft Inc. All rights reserved.