OpenSSL < 0.9.8q / 1.0.0c Multiple Vulnerabilities
High Nessus Plugin ID 51058
SynopsisThe remote web server is affected by multiple vulnerabilities.
DescriptionAccording to its banner, the remote web server is running a version of OpenSSL older than 0.9.8q or 1.0.0c. Such versions are potentially affected by multiple vulnerabilities :
- It may be possible to downgrade the ciphersuite to a weaker version by modifying the stored session cache ciphersuite.
- An error exists in the J-PAKE implementation that could lead to successful validation by someone with no knowledge of the shared secret.
SolutionUpgrade to OpenSSL 0.9.8q / 1.0.0c or later.