First published: Thu Nov 05 2009(Updated: )
Marsh Ray of PhoneFactor has discovered a flaw in the TLS/SSL protocol related to the handling of the session rehandshakes / renegotiations. This flaw can possibly be used in the MITM attacks and allowing an attacker to inject attacker-chosen plain text prefix to the session of the victim. Further details are available in the "Authentication Gap in TLS Renegotiation" blog post: <a href="http://extendedsubset.com/?p=8">http://extendedsubset.com/?p=8</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el3 | 1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el3 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.6-1jpp.3.el3 | 1.4.2-ibm-0:1.4.2.13.6-1jpp.3.el3 |
redhat/java | <1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 | 1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 |
redhat/java | <1.5.0-ibm-1:1.5.0.11.1-1jpp.3.el4 | 1.5.0-ibm-1:1.5.0.11.1-1jpp.3.el4 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el4 | 1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el4 |
redhat/java | <1.6.0-sun-1:1.6.0.19-1jpp.1.el4 | 1.6.0-sun-1:1.6.0.19-1jpp.1.el4 |
redhat/java | <1.5.0-sun-0:1.5.0.22-1jpp.3.el4 | 1.5.0-sun-0:1.5.0.22-1jpp.3.el4 |
redhat/java | <1.6.0-sun-1:1.6.0.22-1jpp.1.el4 | 1.6.0-sun-1:1.6.0.22-1jpp.1.el4 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el4 | 1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el4 |
redhat/java | <1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4 | 1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4 |
redhat/java | <1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4 | 1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4 |
redhat/httpd22 | <0:2.2.10-25.1.ep5.el4 | 0:2.2.10-25.1.ep5.el4 |
redhat/glassfish-jsf | <0:1.2_13-2.ep5.el4 | 0:1.2_13-2.ep5.el4 |
redhat/httpd22 | <0:2.2.14-4.ep5.el4 | 0:2.2.14-4.ep5.el4 |
redhat/jakarta-commons-chain | <0:1.2-2.1.ep5.el4 | 0:1.2-2.1.ep5.el4 |
redhat/jakarta-commons-digester | <0:1.8.1-7.ep5.el4 | 0:1.8.1-7.ep5.el4 |
redhat/jakarta-commons-io | <0:1.4-1.ep5.el4 | 0:1.4-1.ep5.el4 |
redhat/jakarta-commons-modeler | <0:2.0-3.3.ep5.el4 | 0:2.0-3.3.ep5.el4 |
redhat/jakarta-commons-validator | <0:1.3.1-7.4.ep5.el4 | 0:1.3.1-7.4.ep5.el4 |
redhat/jakarta-oro | <0:2.0.8-3jpp.ep1.3.ep5.el4 | 0:2.0.8-3jpp.ep1.3.ep5.el4 |
redhat/jboss-javaee | <0:5.0.1-2.3.ep5.el4 | 0:5.0.1-2.3.ep5.el4 |
redhat/struts12 | <0:1.2.9-2.ep5.el4 | 0:1.2.9-2.ep5.el4 |
redhat/tomcat5 | <0:5.5.28-7.ep5.el4 | 0:5.5.28-7.ep5.el4 |
redhat/tomcat6 | <0:6.0.24-2.ep5.el4 | 0:6.0.24-2.ep5.el4 |
redhat/tomcat-native | <0:1.1.19-2.0.ep5.el4 | 0:1.1.19-2.0.ep5.el4 |
redhat/xerces-j2 | <0:2.9.1-2.2_patch_01.ep5.el4 | 0:2.9.1-2.2_patch_01.ep5.el4 |
redhat/xml-commons-resolver12 | <1:1.2-1.1.ep5.el4 | 1:1.2-1.1.ep5.el4 |
redhat/openssl | <0:0.9.7a-43.17.el4_8.5 | 0:0.9.7a-43.17.el4_8.5 |
redhat/nspr | <0:4.8.4-1.1.el4_8 | 0:4.8.4-1.1.el4_8 |
redhat/nss | <0:3.12.6-1.el4_8 | 0:3.12.6-1.el4_8 |
redhat/gnutls | <0:1.0.20-4.el4_8.7 | 0:1.0.20-4.el4_8.7 |
redhat/httpd | <0:2.2.3-31.el5_4.2 | 0:2.2.3-31.el5_4.2 |
redhat/openssl | <0:0.9.8e-12.el5_4.6 | 0:0.9.8e-12.el5_4.6 |
redhat/openssl097a | <0:0.9.7a-9.el5_4.2 | 0:0.9.7a-9.el5_4.2 |
redhat/nspr | <0:4.8.4-1.el5_4 | 0:4.8.4-1.el5_4 |
redhat/nss | <0:3.12.6-1.el5_4 | 0:3.12.6-1.el5_4 |
redhat/gnutls | <0:1.4.1-3.el5_4.8 | 0:1.4.1-3.el5_4.8 |
redhat/java | <1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5 | 1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5 |
redhat/java | <1.6.0-openjdk-1:1.6.0.0-1.16.b17.el5 | 1.6.0-openjdk-1:1.6.0.0-1.16.b17.el5 |
redhat/java | <1.6.0-openjdk-1:1.6.0.0-1.31.b17.el6_0 | 1.6.0-openjdk-1:1.6.0.0-1.31.b17.el6_0 |
redhat/java | <1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6 | 1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6 |
redhat/rhev-hypervisor | <0:5.4-2.1.12.1.el5_4 | 0:5.4-2.1.12.1.el5_4 |
redhat/httpd | <0:2.2.10-11.ep5.el5 | 0:2.2.10-11.ep5.el5 |
redhat/glassfish-jsf | <0:1.2_13-3.ep5.el5 | 0:1.2_13-3.ep5.el5 |
redhat/httpd | <0:2.2.14-1.2.1.ep5.el5 | 0:2.2.14-1.2.1.ep5.el5 |
redhat/jakarta-commons-chain | <0:1.2-2.1.1.ep5.el5 | 0:1.2-2.1.1.ep5.el5 |
redhat/jakarta-commons-io | <0:1.4-1.1.ep5.el5 | 0:1.4-1.1.ep5.el5 |
redhat/jakarta-oro | <0:2.0.8-3.1.ep5.el5 | 0:2.0.8-3.1.ep5.el5 |
redhat/struts12 | <0:1.2.9-2.ep5.el5 | 0:1.2.9-2.ep5.el5 |
redhat/tomcat5 | <0:5.5.28-7.1.ep5.el5 | 0:5.5.28-7.1.ep5.el5 |
redhat/tomcat6 | <0:6.0.24-2.1.ep5.el5 | 0:6.0.24-2.1.ep5.el5 |
redhat/tomcat-native | <0:1.1.19-2.0.1.ep5.el5 | 0:1.1.19-2.0.1.ep5.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5 | 1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5 |
redhat/aether | <0:1.13.1-13.el7 | 0:1.13.1-13.el7 |
redhat/ant | <0:1.9.2-9.el7 | 0:1.9.2-9.el7 |
redhat/aopalliance | <0:1.0-8.el7 | 0:1.0-8.el7 |
redhat/apache-commons-codec-eap6 | <0:1.4-16.redhat_3.1.ep6.el7 | 0:1.4-16.redhat_3.1.ep6.el7 |
redhat/apache-commons-net | <0:3.2-8.el7 | 0:3.2-8.el7 |
redhat/apache-ivy | <0:2.3.0-4.el7 | 0:2.3.0-4.el7 |
redhat/apache-mime4j | <0:0.6-10.redhat_3.1.ep6.el7 | 0:0.6-10.redhat_3.1.ep6.el7 |
redhat/apache-parent | <0:10-14.el7 | 0:10-14.el7 |
redhat/apache-resource-bundles | <0:2-11.el7 | 0:2-11.el7 |
redhat/atinject | <0:1-13.20100611svn86.el7 | 0:1-13.20100611svn86.el7 |
redhat/bouncycastle | <0:1.46-7.el7 | 0:1.46-7.el7 |
redhat/bsf | <0:2.4.0-19.el7 | 0:2.4.0-19.el7 |
redhat/c3p0 | <0:0.9.1.2-3.ep6.el7 | 0:0.9.1.2-3.ep6.el7 |
redhat/candlepin | <0:0.9.49.3-1.el7 | 0:0.9.49.3-1.el7 |
redhat/candlepin-common | <0:1.0.22-1.el7 | 0:1.0.22-1.el7 |
redhat/candlepin-guice | <0:3.0-2_redhat_1.el7 | 0:3.0-2_redhat_1.el7 |
redhat/candlepin-scl | <0:1-5.el7 | 0:1-5.el7 |
redhat/candlepin-scl-quartz | <0:2.1.5-6.el7 | 0:2.1.5-6.el7 |
redhat/candlepin-scl-rhino | <0:1.7R3-3.el7 | 0:1.7R3-3.el7 |
redhat/cdi-api | <0:1.0-11.SP4.el7 | 0:1.0-11.SP4.el7 |
redhat/cglib | <0:2.2-18.el7 | 0:2.2-18.el7 |
redhat/elasticsearch | <0:0.90.10-7.el7 | 0:0.90.10-7.el7 |
redhat/facter | <1:1.7.6-2.1.el7 | 1:1.7.6-2.1.el7 |
redhat/fasterxml-oss-parent | <0:11-2.ep6.el7 | 0:11-2.ep6.el7 |
redhat/felix-framework | <0:4.2.1-5.el7 | 0:4.2.1-5.el7 |
redhat/foreman | <0:1.7.2.33-1.el7 | 0:1.7.2.33-1.el7 |
redhat/foreman-proxy | <0:1.7.2.5-1.el7 | 0:1.7.2.5-1.el7 |
redhat/foreman-selinux | <0:1.7.2.13-1.el7 | 0:1.7.2.13-1.el7 |
redhat/gettext-commons | <0:0.9.6-7.el7 | 0:0.9.6-7.el7 |
redhat/gofer | <0:2.6.2-2.el7 | 0:2.6.2-2.el7 |
redhat/google-guice | <0:3.1.3-9.el7 | 0:3.1.3-9.el7 |
redhat/gperftools | <0:2.0-3.el7 | 0:2.0-3.el7 |
redhat/groovy | <0:1.8.9-7.el7 | 0:1.8.9-7.el7 |
redhat/guava | <0:13.0-6.el7 | 0:13.0-6.el7 |
redhat/gutterball | <0:1.0.15.0-1.el7 | 0:1.0.15.0-1.el7 |
redhat/hawtjni | <0:1.6-9.el7 | 0:1.6-9.el7 |
redhat/hfsplus-tools | <0:332.14-12.el7 | 0:332.14-12.el7 |
redhat/hibernate3-commons-annotations | <0:4.0.1-5.Final_redhat_2.1.ep6.el7.3 | 0:4.0.1-5.Final_redhat_2.1.ep6.el7.3 |
redhat/hibernate4 | <0:4.2.7-6.SP2_redhat_1.1.ep6.el7 | 0:4.2.7-6.SP2_redhat_1.1.ep6.el7 |
redhat/hibernate4-validator | <0:4.3.1-1.Final_redhat_1.1.ep6.el7.4 | 0:4.3.1-1.Final_redhat_1.1.ep6.el7.4 |
redhat/hibernate-beanvalidation-api | <0:1.0.0-4.7.GA_redhat_2.ep6.el7.3 | 0:1.0.0-4.7.GA_redhat_2.ep6.el7.3 |
redhat/hibernate-jpa | <2.0-api-0:1.0.1-5.Final_redhat_2.1.ep6.el7.4 | 2.0-api-0:1.0.1-5.Final_redhat_2.1.ep6.el7.4 |
redhat/hiera | <0:1.3.1-2.el7 | 0:1.3.1-2.el7 |
redhat/hornetq | <0:2.3.14-1.Final_redhat_1.1.ep6.el7 | 0:2.3.14-1.Final_redhat_1.1.ep6.el7 |
redhat/ipxe | <0:20130517-7.1fm.gitc4bce43.el7 | 0:20130517-7.1fm.gitc4bce43.el7 |
redhat/jackson-annotations | <0:2.3.0-3.ep6.el7 | 0:2.3.0-3.ep6.el7 |
redhat/jackson-core | <0:2.3.0-1.ep6.el7 | 0:2.3.0-1.ep6.el7 |
redhat/jackson-databind | <0:2.3.0-2.ep6.el7 | 0:2.3.0-2.ep6.el7 |
redhat/jackson-datatype-hibernate | <0:2.3.0-1.ep6.el7 | 0:2.3.0-1.ep6.el7 |
redhat/jackson-jaxrs-providers | <0:2.3.0-5.ep6.el7 | 0:2.3.0-5.ep6.el7 |
redhat/jackson-module-jaxb-annotations | <0:2.3.0-2.ep6.el7 | 0:2.3.0-2.ep6.el7 |
redhat/janino | <0:2.6.1-2.el7 | 0:2.6.1-2.el7 |
redhat/jansi | <0:1.9-7.el7 | 0:1.9-7.el7 |
redhat/jansi-native | <0:1.4-10.el7 | 0:1.4-10.el7 |
redhat/jboss-ejb | <3.1-api-0:1.0.2-10.el7 | 3.1-api-0:1.0.2-10.el7 |
redhat/jboss-el | <2.2-api-0:1.0.1-0.7.20120212git2fabd8.el7 | 2.2-api-0:1.0.1-0.7.20120212git2fabd8.el7 |
redhat/jboss-interceptors | <1.1-api-0:1.0.2-0.9.20120319git49a904.el7 | 1.1-api-0:1.0.2-0.9.20120319git49a904.el7 |
redhat/jboss-jaxrpc | <1.1-api-0:1.0.1-7.el7 | 1.1-api-0:1.0.1-7.el7 |
redhat/jboss-logging | <0:3.1.4-1.GA_redhat_1.1.ep6.el7 | 0:3.1.4-1.GA_redhat_1.1.ep6.el7 |
redhat/jboss-parent | <0:14-2.el7 | 0:14-2.el7 |
redhat/jboss-servlet | <3.0-api-0:1.0.1-9.el7 | 3.0-api-0:1.0.1-9.el7 |
redhat/jboss-specs-parent | <0:1.0.0-0.7.Beta2.el7 | 0:1.0.0-0.7.Beta2.el7 |
redhat/jboss-transaction | <1.1-api-0:1.0.1-8.el7 | 1.1-api-0:1.0.1-8.el7 |
redhat/jsch | <0:0.1.50-5.el7 | 0:0.1.50-5.el7 |
redhat/jsoup | <0:1.6.1-10.el7 | 0:1.6.1-10.el7 |
redhat/jsr | <305-0:0-0.18.20090319svn.el7 | 305-0:0-0.18.20090319svn.el7 |
redhat/jsr | <311-0:1.1.1-6.el7 | 311-0:1.1.1-6.el7 |
redhat/jzlib | <0:1.1.1-6.el7 | 0:1.1.1-6.el7 |
redhat/katello | <0:2.2.0.14-1.el7 | 0:2.2.0.14-1.el7 |
redhat/katello-agent | <0:2.2.5-1.el7 | 0:2.2.5-1.el7 |
redhat/katello-certs-tools | <0:2.2.1-1.el7 | 0:2.2.1-1.el7 |
redhat/katello-installer-base | <0:2.3.17-1.el7 | 0:2.3.17-1.el7 |
redhat/katello-utils | <0:2.2.5-1.el7 | 0:2.2.5-1.el7 |
redhat/libdb | <0:5.3.21-17.el7_0.1 | 0:5.3.21-17.el7_0.1 |
redhat/liquibase | <0:3.1.0-1.el7 | 0:3.1.0-1.el7 |
redhat/livecd-tools | <1:20.4-1.5.el7 | 1:20.4-1.5.el7 |
redhat/logback | <0:1.0.13-6.el7 | 0:1.0.13-6.el7 |
redhat/lucene4 | <0:4.6.1-1.el7 | 0:4.6.1-1.el7 |
redhat/maven | <0:3.0.5-16.el7 | 0:3.0.5-16.el7 |
redhat/maven2 | <0:2.2.1-47.el7 | 0:2.2.1-47.el7 |
redhat/maven-artifact-resolver | <1:1.0-10.el7 | 1:1.0-10.el7 |
redhat/maven-common-artifact-filters | <0:1.4-11.el7 | 0:1.4-11.el7 |
redhat/maven-compiler-plugin | <0:3.1-4.el7 | 0:3.1-4.el7 |
redhat/maven-file-management | <1:1.2.1-8.el7 | 1:1.2.1-8.el7 |
redhat/maven-filtering | <0:1.1-3.el7 | 0:1.1-3.el7 |
redhat/maven-invoker | <0:2.1.1-9.el7 | 0:2.1.1-9.el7 |
redhat/maven-parent | <0:20-5.el7 | 0:20-5.el7 |
redhat/maven-release | <0:2.2.1-12.el7 | 0:2.2.1-12.el7 |
redhat/maven-remote-resources-plugin | <0:1.4-7.el7 | 0:1.4-7.el7 |
redhat/maven-scm | <0:1.8.1-2.el7 | 0:1.8.1-2.el7 |
redhat/maven-shared-incremental | <0:1.1-6.el7 | 0:1.1-6.el7 |
redhat/maven-shared-io | <1:1.1-7.el7 | 1:1.1-7.el7 |
redhat/maven-shared-utils | <0:0.4-3.el7 | 0:0.4-3.el7 |
redhat/maven-wagon | <0:2.4-3.el7 | 0:2.4-3.el7 |
redhat/modello | <0:1.7-4.el7 | 0:1.7-4.el7 |
redhat/mongodb | <0:2.4.9-3.el7 | 0:2.4.9-3.el7 |
redhat/nekohtml | <0:1.9.14-13.el7 | 0:1.9.14-13.el7 |
redhat/netty | <0:3.6.7-1.Final_redhat_1.1.ep6.el7 | 0:3.6.7-1.Final_redhat_1.1.ep6.el7 |
redhat/oauth | <0:20100601-5.el7 | 0:20100601-5.el7 |
redhat/objectweb-asm | <0:3.3.1-9.el7 | 0:3.3.1-9.el7 |
redhat/openscap | <0:1.2.4-1.el7 | 0:1.2.4-1.el7 |
redhat/plexus-build-api | <0:0.0.7-11.el7 | 0:0.0.7-11.el7 |
redhat/plexus-cipher | <0:1.7-5.el7 | 0:1.7-5.el7 |
redhat/plexus-classworlds | <0:2.4.2-8.el7 | 0:2.4.2-8.el7 |
redhat/plexus-compiler | <0:2.2-7.el7 | 0:2.2-7.el7 |
redhat/plexus-component-api | <0:1.0-0.16.alpha15.el7 | 0:1.0-0.16.alpha15.el7 |
redhat/plexus-containers | <0:1.5.5-14.el7 | 0:1.5.5-14.el7 |
redhat/plexus-interactivity | <0:1.0-0.14.alpha6.el7 | 0:1.0-0.14.alpha6.el7 |
redhat/plexus-interpolation | <0:1.15-8.el7 | 0:1.15-8.el7 |
redhat/plexus-resources | <0:1.0-0.15.a7.el7 | 0:1.0-0.15.a7.el7 |
redhat/plexus-sec-dispatcher | <0:1.4-13.el7 | 0:1.4-13.el7 |
redhat/plexus-utils | <0:3.0.9-9.el7 | 0:3.0.9-9.el7 |
redhat/plexus-velocity | <0:1.1.8-16.el7 | 0:1.1.8-16.el7 |
redhat/pulp | <0:2.6.0.15-1.el7 | 0:2.6.0.15-1.el7 |
redhat/pulp-docker | <0:0.2.5-1.el7 | 0:0.2.5-1.el7 |
redhat/pulp-katello | <0:0.5-1.el7 | 0:0.5-1.el7 |
redhat/pulp-puppet | <0:2.6.0.15-1.el7 | 0:2.6.0.15-1.el7 |
redhat/pulp-rpm | <0:2.6.0.15-1.el7 | 0:2.6.0.15-1.el7 |
redhat/puppet | <0:3.6.2-4.el7 | 0:3.6.2-4.el7 |
redhat/puppetlabs-stdlib | <0:4.2.1-1.20140510git08b00d9.el7 | 0:4.2.1-1.20140510git08b00d9.el7 |
redhat/python-amqp | <0:1.4.6-1.el7 | 0:1.4.6-1.el7 |
redhat/python-anyjson | <0:0.3.3-5.el7 | 0:0.3.3-5.el7 |
redhat/python-billiard | <1:3.3.0.17-1.el7 | 1:3.3.0.17-1.el7 |
redhat/python-blinker | <0:1.3-2.el7 | 0:1.3-2.el7 |
redhat/python-celery | <0:3.1.11-1.el7 | 0:3.1.11-1.el7 |
redhat/python-cherrypy | <0:3.2.2-3.el7 | 0:3.2.2-3.el7 |
redhat/python-crane | <0:0.2.2-1.el7 | 0:0.2.2-1.el7 |
redhat/python-flask | <1:0.10.1-4.el7 | 1:0.10.1-4.el7 |
redhat/python-httplib2 | <0:0.6.0-6.el7 | 0:0.6.0-6.el7 |
redhat/python-isodate | <0:0.5.0-4.pulp.el7 | 0:0.5.0-4.pulp.el7 |
redhat/python-itsdangerous | <0:0.23-1.el7 | 0:0.23-1.el7 |
redhat/python-jinja2 | <0:2.7.2-2.el7 | 0:2.7.2-2.el7 |
redhat/python-kombu | <1:3.0.24-10.pulp.el7 | 1:3.0.24-10.pulp.el7 |
redhat/python-mongoengine | <0:0.7.10-2.el7 | 0:0.7.10-2.el7 |
redhat/python-nectar | <0:1.3.1-2.el7 | 0:1.3.1-2.el7 |
redhat/python-oauth2 | <0:1.5.211-8.el7 | 0:1.5.211-8.el7 |
redhat/python-okaara | <0:1.0.32-1.el7 | 0:1.0.32-1.el7 |
redhat/python-pymongo | <0:2.5.2-3.el7 | 0:2.5.2-3.el7 |
redhat/python-qpid | <0:0.30-6.el7 | 0:0.30-6.el7 |
redhat/python-requests | <0:2.4.3-1.el7 | 0:2.4.3-1.el7 |
redhat/python-semantic-version | <0:2.2.0-3.el7 | 0:2.2.0-3.el7 |
redhat/python-simplejson | <0:3.2.0-1.el7 | 0:3.2.0-1.el7 |
redhat/python-webpy | <0:0.37-3.el7 | 0:0.37-3.el7 |
redhat/python-werkzeug | <0:0.9.1-1.el7 | 0:0.9.1-1.el7 |
redhat/qpid-cpp | <0:0.30-9.el7 | 0:0.30-9.el7 |
redhat/qpid-dispatch | <0:0.4-7.el7 | 0:0.4-7.el7 |
redhat/qpid-java | <0:0.30-3.el7 | 0:0.30-3.el7 |
redhat/qpid-proton | <0:0.9-4.el7 | 0:0.9-4.el7 |
redhat/qpid-qmf | <0:0.30-5.el7 | 0:0.30-5.el7 |
redhat/qpid-tools | <0:0.30-4.el7 | 0:0.30-4.el7 |
redhat/resteasy | <0:2.3.8-4.Final_redhat_3.1.ep6.el7 | 0:2.3.8-4.Final_redhat_3.1.ep6.el7 |
redhat/ruby193-facter | <0:1.6.18-5.el7 | 0:1.6.18-5.el7 |
redhat/ruby193-rubygem-addressable | <0:2.3.5-2.el7 | 0:2.3.5-2.el7 |
redhat/ruby193-rubygem-algebrick | <0:0.4.0-3.el7 | 0:0.4.0-3.el7 |
redhat/ruby193-rubygem-ancestry | <0:2.0.0-1.el7 | 0:2.0.0-1.el7 |
redhat/ruby193-rubygem-anemone | <0:0.7.2-11.el7 | 0:0.7.2-11.el7 |
redhat/ruby193-rubygem-angular-rails-templates | <0:0.1.2-1.el7 | 0:0.1.2-1.el7 |
redhat/ruby193-rubygem-ansi | <0:1.4.3-3.el7 | 0:1.4.3-3.el7 |
redhat/ruby193-rubygem-apipie-params | <0:0.0.3-2.el7 | 0:0.0.3-2.el7 |
redhat/ruby193-rubygem-apipie-rails | <0:0.2.5-1.el7 | 0:0.2.5-1.el7 |
redhat/ruby193-rubygem-archive-tar-minitar | <0:0.5.2-9.el7 | 0:0.5.2-9.el7 |
redhat/ruby193-rubygem-audited | <0:3.0.0-5.el7 | 0:3.0.0-5.el7 |
redhat/ruby193-rubygem-audited-activerecord | <0:3.0.0-8.el7 | 0:3.0.0-8.el7 |
redhat/ruby193-rubygem-autoparse | <0:0.3.3-2.el7 | 0:0.3.3-2.el7 |
redhat/ruby193-rubygem-bastion | <0:0.3.0.10-1.el7 | 0:0.3.0.10-1.el7 |
redhat/ruby193-rubygem-commonjs | <0:0.2.7-1.el7 | 0:0.2.7-1.el7 |
redhat/ruby193-rubygem-daemons | <0:1.1.4-10.el7 | 0:1.1.4-10.el7 |
redhat/ruby193-rubygem-deface | <0:0.7.2-7.el7 | 0:0.7.2-7.el7 |
redhat/ruby193-rubygem-docker-api | <0:1.17.0-1.1.el7 | 0:1.17.0-1.1.el7 |
redhat/ruby193-rubygem-dynflow | <0:0.7.7.9-1.el7 | 0:0.7.7.9-1.el7 |
redhat/ruby193-rubygem-excon | <0:0.38.0-1.el7 | 0:0.38.0-1.el7 |
redhat/ruby193-rubygem-extlib | <0:0.9.16-2.el7 | 0:0.9.16-2.el7 |
redhat/ruby193-rubygem-faraday | <0:0.8.8-2.el7 | 0:0.8.8-2.el7 |
redhat/ruby193-rubygem-ffi | <0:1.9.3-3.el7 | 0:1.9.3-3.el7 |
redhat/ruby193-rubygem-fog | <0:1.24.0-3.el7 | 0:1.24.0-3.el7 |
redhat/ruby193-rubygem-fog-brightbox | <0:0.0.1-2.el7 | 0:0.0.1-2.el7 |
redhat/ruby193-rubygem-fog-core | <0:1.24.0-1.el7 | 0:1.24.0-1.el7 |
redhat/ruby193-rubygem-fog-json | <0:1.0.0-2.1.el7 | 0:1.0.0-2.1.el7 |
redhat/ruby193-rubygem-fog-radosgw | <0:0.0.3-1.el7 | 0:0.0.3-1.el7 |
redhat/ruby193-rubygem-fog-sakuracloud | <0:0.1.1-1.el7 | 0:0.1.1-1.el7 |
redhat/ruby193-rubygem-fog-softlayer | <0:0.3.9-1.el7 | 0:0.3.9-1.el7 |
redhat/ruby193-rubygem-fog-xml | <0:0.1.0-1.el7 | 0:0.1.0-1.el7 |
redhat/ruby193-rubygem-foreigner | <0:1.4.2-1.el7 | 0:1.4.2-1.el7 |
redhat/ruby193-rubygem-foreman-tasks | <0:0.6.15.4-1.el7 | 0:0.6.15.4-1.el7 |
redhat/ruby193-rubygem-formatador | <0:0.2.1-9.el7 | 0:0.2.1-9.el7 |
redhat/ruby193-rubygem-google-api-client | <0:0.6.4-2.el7 | 0:0.6.4-2.el7 |
redhat/ruby193-rubygem-haml | <0:3.1.6-6.el7 | 0:3.1.6-6.el7 |
redhat/ruby193-rubygem-haml-rails | <0:0.3.4-8.el7 | 0:0.3.4-8.el7 |
redhat/ruby193-rubygem-hashr | <0:0.0.22-5.el7 | 0:0.0.22-5.el7 |
redhat/ruby193-rubygem-hooks | <0:0.2.2-7.el7 | 0:0.2.2-7.el7 |
redhat/ruby193-rubygem-hpricot | <0:0.8.6-11.el7 | 0:0.8.6-11.el7 |
redhat/ruby193-rubygem-ipaddress | <0:0.8.0-6.el7 | 0:0.8.0-6.el7 |
redhat/ruby193-rubygem-jquery-ui-rails | <0:4.0.2-8.el7 | 0:4.0.2-8.el7 |
redhat/ruby193-rubygem-justified | <0:0.0.4-4.el7 | 0:0.0.4-4.el7 |
redhat/ruby193-rubygem-jwt | <0:0.1.8-2.el7 | 0:0.1.8-2.el7 |
redhat/ruby193-rubygem-katello | <0:2.2.0.65-1.el7 | 0:2.2.0.65-1.el7 |
redhat/ruby193-rubygem-launchy | <0:2.3.0-2.el7 | 0:2.3.0-2.el7 |
redhat/ruby193-rubygem-less | <0:2.5.1-2.1.el7 | 0:2.5.1-2.1.el7 |
redhat/ruby193-rubygem-less-rails | <0:2.5.0-1.el7 | 0:2.5.0-1.el7 |
redhat/ruby193-rubygem-little-plugger | <0:1.1.3-17.el7 | 0:1.1.3-17.el7 |
redhat/ruby193-rubygem-logging | <0:1.8.1-26.el7 | 0:1.8.1-26.el7 |
redhat/ruby193-rubygem-multipart-post | <0:1.2.0-3.el7 | 0:1.2.0-3.el7 |
redhat/ruby193-rubygem-net-ldap | <0:0.3.1-3.el7 | 0:0.3.1-3.el7 |
redhat/ruby193-rubygem-net-scp | <0:1.1.0-5.el7 | 0:1.1.0-5.el7 |
redhat/ruby193-rubygem-net-ssh | <0:2.6.7-5.el7 | 0:2.6.7-5.el7 |
redhat/ruby193-rubygem-nokogiri | <0:1.5.11-1.el7 | 0:1.5.11-1.el7 |
redhat/ruby193-rubygem-oauth | <0:0.4.7-8.el7 | 0:0.4.7-8.el7 |
redhat/ruby193-rubygem-openscap | <0:0.4.2-2.el7 | 0:0.4.2-2.el7 |
redhat/ruby193-rubygem-passenger | <0:4.0.18-19.el7 | 0:4.0.18-19.el7 |
redhat/ruby193-rubygem-pg | <0:0.12.2-10.el7 | 0:0.12.2-10.el7 |
redhat/ruby193-rubygem-rabl | <0:0.9.0-1.el7 | 0:0.9.0-1.el7 |
redhat/ruby193-rubygem-rbovirt | <0:0.0.29-1.el7 | 0:0.0.29-1.el7 |
redhat/ruby193-rubygem-rbvmomi | <0:1.6.0-3.el7 | 0:1.6.0-3.el7 |
redhat/ruby193-rubygem-rest-client | <0:1.6.7-1.el7 | 0:1.6.7-1.el7 |
redhat/ruby193-rubygem-robotex | <0:1.0.0-16.el7 | 0:1.0.0-16.el7 |
redhat/ruby193-rubygem-ruby2ruby | <0:2.0.1-9.el7 | 0:2.0.1-9.el7 |
redhat/ruby193-rubygem-ruby-libvirt | <0:0.5.1-1.el7 | 0:0.5.1-1.el7 |
redhat/ruby193-rubygem-runcible | <0:1.3.5-1.el7 | 0:1.3.5-1.el7 |
redhat/ruby193-rubygem-safemode | <0:1.2.1-1.el7 | 0:1.2.1-1.el7 |
redhat/ruby193-rubygem-sass | <0:3.2.13-1.el7 | 0:3.2.13-1.el7 |
redhat/ruby193-rubygem-scaptimony | <0:0.3.0.1-1.el7 | 0:0.3.0.1-1.el7 |
redhat/ruby193-rubygem-sequel | <0:3.45.0-6.el7 | 0:3.45.0-6.el7 |
redhat/ruby193-rubygem-signet | <0:0.4.5-2.el7 | 0:0.4.5-2.el7 |
redhat/ruby193-rubygem-sprockets | <0:2.10.1-3.el7 | 0:2.10.1-3.el7 |
redhat/ruby193-rubygem-sshkey | <0:1.6.0-3.el7 | 0:1.6.0-3.el7 |
redhat/ruby193-rubygem-tire | <0:0.6.2-1.el7 | 0:0.6.2-1.el7 |
redhat/ruby193-rubygem-trollop | <0:2.0-5.el7 | 0:2.0-5.el7 |
redhat/ruby193-rubygem-unf | <0:0.1.3-4.el7 | 0:0.1.3-4.el7 |
redhat/ruby193-rubygem-uuidtools | <0:2.1.3-6.el7 | 0:2.1.3-6.el7 |
redhat/ruby193-rubygem-wicked | <0:1.1.0-1.el7 | 0:1.1.0-1.el7 |
redhat/ruby193-ruby-wrapper | <0:0.0.2-6.el7 | 0:0.0.2-6.el7 |
redhat/ruby-augeas | <0:0.5.0-1.el7 | 0:0.5.0-1.el7 |
redhat/rubygem-ansi | <0:1.4.3-3.el7 | 0:1.4.3-3.el7 |
redhat/rubygem-apipie-bindings | <0:0.0.11-1.el7 | 0:0.0.11-1.el7 |
redhat/rubygem-clamp | <0:0.6.2-2.el7 | 0:0.6.2-2.el7 |
redhat/rubygem-fastercsv | <0:1.5.4-10.el7 | 0:1.5.4-10.el7 |
redhat/rubygem-ffi | <0:1.4.0-3.el7 | 0:1.4.0-3.el7 |
redhat/rubygem-gssapi | <0:1.1.2-4.el7 | 0:1.1.2-4.el7 |
redhat/rubygem-hashie | <0:2.0.5-2.el7 | 0:2.0.5-2.el7 |
redhat/rubygem-highline | <0:1.6.21-1.el7 | 0:1.6.21-1.el7 |
redhat/rubygem-kafo | <0:0.6.5.9-1.el7 | 0:0.6.5.9-1.el7 |
redhat/rubygem-little-plugger | <0:1.1.3-17.el7 | 0:1.1.3-17.el7 |
redhat/rubygem-locale | <0:2.0.9-7.el7 | 0:2.0.9-7.el7 |
redhat/rubygem-logging | <0:1.8.1-26.el7 | 0:1.8.1-26.el7 |
redhat/rubygem-mime-types | <0:1.19-7.el7 | 0:1.19-7.el7 |
redhat/rubygem-oauth | <0:0.4.7-8.el7 | 0:0.4.7-8.el7 |
redhat/rubygem-passenger | <0:4.0.18-19.el7 | 0:4.0.18-19.el7 |
redhat/rubygem-powerbar | <0:1.0.11-8.el7 | 0:1.0.11-8.el7 |
redhat/rubygem-rack | <1:1.4.1-13.el7 | 1:1.4.1-13.el7 |
redhat/rubygem-rack-protection | <0:1.5.0-7.el7 | 0:1.5.0-7.el7 |
redhat/rubygem-rake | <0:0.9.2.2-41.el7 | 0:0.9.2.2-41.el7 |
redhat/rubygem-rb-readline | <0:0.5.1-1.el7 | 0:0.5.1-1.el7 |
redhat/rubygem-rest-client | <0:1.6.7-1.el7 | 0:1.6.7-1.el7 |
redhat/rubygem-rkerberos | <0:0.1.2-3.el7 | 0:0.1.2-3.el7 |
redhat/rubygem-rubyipmi | <0:0.10.0-1.el7 | 0:0.10.0-1.el7 |
redhat/rubygem-satyr | <0:0.2-1.el7 | 0:0.2-1.el7 |
redhat/rubygem-sinatra | <1:1.3.6-27.el7 | 1:1.3.6-27.el7 |
redhat/rubygem-tilt | <0:1.3.3-18.el7 | 0:1.3.3-18.el7 |
redhat/ruby-rgen | <0:0.6.5-2.el7 | 0:0.6.5-2.el7 |
redhat/ruby-shadow | <0:1.4.1-21.el7 | 0:1.4.1-21.el7 |
redhat/saslwrapper | <0:0.22-5.el7 | 0:0.22-5.el7 |
redhat/sigar | <0:1.6.5-0.9.git58097d9.el7 | 0:1.6.5-0.9.git58097d9.el7 |
redhat/sisu | <0:2.3.0-11.el7 | 0:2.3.0-11.el7 |
redhat/snappy-java | <0:1.0.4-2.el7 | 0:1.0.4-2.el7 |
redhat/v8 | <1:3.14.5.10-11.el7 | 1:3.14.5.10-11.el7 |
redhat/xbean | <0:3.13-6.el7 | 0:3.13-6.el7 |
redhat/xpp3 | <0:1.1.3.8-11.el7 | 0:1.1.3.8-11.el7 |
redhat/xstream | <0:1.3.1-10.el7 | 0:1.3.1-10.el7 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el4_8 | 1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el4_8 |
redhat/java | <1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el4_8 | 1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el4_8 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el5 | 1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el5 |
redhat/java | <1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el5 | 1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | 1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 |
redhat/java | <1.5.0-ibm-1:1.5.0.11.1-1jpp.3.el5 | 1.5.0-ibm-1:1.5.0.11.1-1jpp.3.el5 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el5 | 1.4.2-ibm-0:1.4.2.13.4-1jpp.1.el5 |
redhat/java | <1.6.0-sun-1:1.6.0.19-1jpp.1.el5 | 1.6.0-sun-1:1.6.0.19-1jpp.1.el5 |
redhat/java | <1.5.0-sun-0:1.5.0.22-1jpp.3.el5 | 1.5.0-sun-0:1.5.0.22-1jpp.3.el5 |
redhat/java | <1.6.0-sun-1:1.6.0.22-1jpp.1.el5 | 1.6.0-sun-1:1.6.0.22-1jpp.1.el5 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el5 | 1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el5 |
redhat/java | <1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5 | 1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5 | 1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5 |
maven/org.apache.tomcat:tomcat | >=5.0.0<5.5.33 | 5.5.33 |
maven/org.apache.tomcat:tomcat | >=6.0.0<6.0.32 | 6.0.32 |
maven/org.apache.tomcat:tomcat | >=7.0.0<7.0.10 | 7.0.10 |
Apache HTTP server | <=2.2.14 | |
GNU GnuTLS | <=2.8.5 | |
Mozilla NSS | <=3.12.4 | |
OpenSSL OpenSSL | <=0.9.8k | |
OpenSSL OpenSSL | =1.0 | |
Canonical Ubuntu Linux | =8.04 | |
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =9.04 | |
Canonical Ubuntu Linux | =9.10 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =10.10 | |
Debian Debian Linux | =4.0 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =6.0 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Fedoraproject Fedora | =11 | |
Fedoraproject Fedora | =12 | |
Fedoraproject Fedora | =13 | |
Fedoraproject Fedora | =14 | |
F5 Nginx | >=0.1.0<=0.8.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)