CVE-2020-1968: Raccoon attack
Last updated 18 August 2025
Other sources
The Raccoon attack exploits a flaw in the TLS specification which can ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u8 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.6.3-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.0.2w
Event History
Frequently Asked Questions
What is CVE-2020-1968?
CVE-2020-1968 is a vulnerability that exploits a flaw in the TLS specification, allowing an attacker to compute the pre-master secret in connections using a Diffie-Hellman based cipher suite.
What is the severity of CVE-2020-1968?
The severity of CVE-2020-1968 is medium, with a severity value of 3.7.
Which software versions are affected by CVE-2020-1968?
CVE-2020-1968 affects OpenSSL versions up to but excluding 1.0.2 and 1.1.1n-0+deb10u3, 1.1.1n-0+deb10u6, 1.1.1w-0+deb11u1, 1.1.1n-0+deb11u5, 3.0.11-1~deb12u1, 3.0.11-1~deb12u2, 3.0.11-1, 3.0.12-1.
How can I fix CVE-2020-1968?
To fix CVE-2020-1968, you should update your OpenSSL software to a version that includes the security patch.
Where can I find more information about CVE-2020-1968?
You can find more information about CVE-2020-1968 on the official OpenSSL website and the provided references.