{ "schema_version": "1.4.0", "id": "GHSA-jcj6-c96p-jcmm", "modified": "2025-04-12T12:46:47Z", "published": "2022-05-13T01:13:25Z", "aliases": [ "CVE-2015-2808" ], "details": "The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the \"Bar Mitzvah\" issue.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2808" }, { "type": "WEB", "url": "https://www.secpod.com/blog/cve-2015-2808-bar-mitzvah-attack-in-rc4-2" }, { "type": "WEB", "url": "https://www.blackhat.com/docs/asia-15/materials/asia-15-Mantin-Bar-Mitzvah-Attack-Breaking-SSL-With-13-Year-Old-RC4-Weakness-wp.pdf" }, { "type": "WEB", "url": "https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098709" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201512-10" }, { "type": "WEB", "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10163" }, { "type": "WEB", "url": "https://kb.juniper.net/JSA10783" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05193347" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04711380" }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04708650" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773256" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773241" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04773119" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04772190" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04770140" }, { "type": "WEB", "url": "https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04687922" }, { "type": "WEB", "url": "http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034" }, { "type": "WEB", "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705" }, { "type": "WEB", "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143456209711959&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143629696317098&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143741441012338&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143817021313142&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143817899717054&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=143818140118771&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144043644216842&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144059660127919&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144059703728085&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144060576831314&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144060606031437&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144069189622016&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144102017024820&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144104533800819&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144104565600964&w=2" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=144493176821532&w=2" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1006.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1007.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1020.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1021.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1091.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1228.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1229.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1230.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1241.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1242.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1243.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2015-1526.html" }, { "type": "WEB", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV71888" }, { "type": "WEB", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV71892" }, { "type": "WEB", "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21883640" }, { "type": "WEB", "url": "http://www-304.ibm.com/support/docview.wss?uid=swg21903565" }, { "type": "WEB", "url": "http://www-304.ibm.com/support/docview.wss?uid=swg21960015" }, { "type": "WEB", "url": "http://www-304.ibm.com/support/docview.wss?uid=swg21960769" }, { "type": "WEB", "url": "http://www.debian.org/security/2015/dsa-3316" }, { "type": "WEB", "url": "http://www.debian.org/security/2015/dsa-3339" }, { "type": "WEB", "url": "http://www.huawei.com/en/psirt/security-advisories/hw-454055" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/73684" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/91787" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032599" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032600" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032707" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032708" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032734" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032788" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032858" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032868" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032910" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1032990" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033071" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033072" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033386" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033415" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033431" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033432" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033737" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033769" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1036222" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2696-1" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2706-1" }, { "type": "WEB", "url": "http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454055.htm" } ], "database_specific": { "cwe_ids": [ "CWE-327" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-04-01T02:00:00Z" } }