CVE-2005-2969: Medium severity OpenSSL OpenSSL vulnerability
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSLOPMSIESSLV2RSAPADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2969?
CVE-2005-2969 has a moderate severity rating due to its exploitation potential in SSL/TLS communication.
How do I fix CVE-2005-2969?
To fix CVE-2005-2969, upgrade OpenSSL to version 0.9.7h or later, or to version 0.9.8a or later.
Which versions of OpenSSL are affected by CVE-2005-2969?
CVE-2005-2969 affects OpenSSL versions from 0.9.7a to 0.9.7g and 0.9.8 before 0.9.8a.
What kind of attack does CVE-2005-2969 allow?
CVE-2005-2969 allows remote attackers to perform protocol version rollback attacks.
Is there a workaround for CVE-2005-2969 if I can't upgrade?
There is no recommended workaround for CVE-2005-2969; upgrading is the only effective mitigation.