Upstream information

CVE-2015-8960 at MITRE

Description

The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.

SUSE information

Overall state of this security issue: Pending

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 6.8 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network Network
Access Complexity Medium Medium
Authentication None None
Confidentiality Impact Partial Partial
Integrity Impact Partial Partial
Availability Impact Partial Partial
SUSE Bugzilla entry: 941124 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.

Product(s) Source package State
SUSE Linux Enterprise Desktop 11 SP3 openssl Not affected
SUSE Linux Enterprise Desktop 11 SP4 openssl Not affected
SUSE Linux Enterprise Desktop 12 GA openssl Not affected
SUSE Linux Enterprise Desktop 12 SP2 openssl Already fixed
SUSE Linux Enterprise SDK 11 SP3 openssl Not affected
SUSE Linux Enterprise SDK 11 SP4 openssl Not affected
SUSE Linux Enterprise SDK 12 GA openssl Not affected
SUSE Linux Enterprise SDK 12 SP2 openssl Already fixed
SUSE Linux Enterprise Server 11 SP3 openssl Not affected
SUSE Linux Enterprise Server 11 SP4 openssl Not affected
SUSE Linux Enterprise Server 12 GA openssl Not affected
SUSE Linux Enterprise Server 12 SP2 openssl Already fixed
SUSE Linux Enterprise Server for VMWare 11 SP3 openssl Not affected