CVE-2004-2681: XSS
Published Dec 31, 2004
·Updated
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.
Affected Software
1 affected component
Peersec Networks Matrixssl<=1.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 6, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2681?
CVE-2004-2681 is considered a high severity vulnerability due to the potential for remote session hijacking.
2
How do I fix CVE-2004-2681?
To fix CVE-2004-2681, update MatrixSSL to version 1.1 or later, which addresses the session key caching vulnerability.
3
What type of attack is possible due to CVE-2004-2681?
CVE-2004-2681 allows remote attackers to hijack an active session by exploiting the indefinite caching of session keys.
4
Which versions of MatrixSSL are affected by CVE-2004-2681?
CVE-2004-2681 affects all versions of MatrixSSL prior to version 1.1.
5
Is there a workaround for CVE-2004-2681 until I can update?
There are no effective workarounds for CVE-2004-2681; it is strongly recommended to upgrade to a secure version.