REDHAT-BUG-1289841: Medium severity Unknown TLS 1.2 vulnerability
A new class of transcript collision attacks on the use of MD5 in key exchange protocol was found in TLS 1.2. Due to several high-profile attacks against MD5, there is now consensus among certification authorities and software vendors to stop issuing and accepting new MD5 certificates. However MD5 continues to be supported in key exchange protocol for TLS 1.2 and also in IPSec and SSH-2. A almost-practical impersonation and downgrade attack was demostrated for IKEv2 and SSH-2 and also a concrete credential forwarding attack against TLS 1.2 client authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1289841?
The severity of REDHAT-BUG-1289841 is classified as medium, with a score of 4.
How do I fix REDHAT-BUG-1289841?
To fix REDHAT-BUG-1289841, it is recommended to avoid the use of MD5 in TLS 1.2 and migrate to more secure hashing algorithms.
What are the potential impacts of REDHAT-BUG-1289841?
The potential impacts of REDHAT-BUG-1289841 include vulnerability to transcript collision attacks which can compromise key exchange protocols.
Which protocols are affected by REDHAT-BUG-1289841?
REDHAT-BUG-1289841 affects the use of MD5 in TLS 1.2, IPSec, and SSH-2 protocols.
Is there a consensus about the use of MD5 in REDHAT-BUG-1289841?
Yes, there is a consensus among certification authorities and software vendors to discontinue issuing and accepting new MD5 certificates due to its vulnerabilities.