First published: Mon Mar 22 1999(Updated: )
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSL | <0.9.2b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0428 is considered a critical security vulnerability due to its potential to allow unauthorized access to SSL sessions.
To fix CVE-1999-0428, upgrade OpenSSL to a version later than 0.9.2b to prevent SSL session reuse.
CVE-1999-0428 affects OpenSSL versions up to and including 0.9.2b.
Yes, CVE-1999-0428 can compromise secure communications by allowing attackers to reuse SSL sessions.
Web servers and applications using vulnerable versions of OpenSSL are most likely to be targeted by CVE-1999-0428.