Guest Kovalski Posted June 23, 2012 Report Posted June 23, 2012 Bugtraq ID: 51281Class: UnknownCVE: CVE-2011-4108CVE-2011-4109CVE-2011-4576CVE-2011-4577CVE-2011-4619CVE-2012-0027Remote: YesLocal: NoPublished: Jan 05 2012 12:00AMUpdated: Jun 23 2012 12:50AMCredit: Nadhem Alfardan and Kenny Paterson, Information Security Group at Royal Holloway, University of London, Ben Laurie, Adam Langley, Andrew Chi, BBN Technologies and Andrey KulikovVulnerable: Ubuntu Ubuntu Linux 8.04 LTS sparcUbuntu Ubuntu Linux 8.04 LTS powerpcUbuntu Ubuntu Linux 8.04 LTS lpiaUbuntu Ubuntu Linux 8.04 LTS i386Ubuntu Ubuntu Linux 8.04 LTS amd64Ubuntu Ubuntu Linux 11.10 i386Ubuntu Ubuntu Linux 11.10 amd64Ubuntu Ubuntu Linux 11.04 powerpcUbuntu Ubuntu Linux 11.04 i386Ubuntu Ubuntu Linux 11.04 ARMUbuntu Ubuntu Linux 11.04 amd64Ubuntu Ubuntu Linux 10.10 powerpcUbuntu Ubuntu Linux 10.10 i386Ubuntu Ubuntu Linux 10.10 ARMUbuntu Ubuntu Linux 10.10 amd64Ubuntu Ubuntu Linux 10.04 sparcUbuntu Ubuntu Linux 10.04 powerpcUbuntu Ubuntu Linux 10.04 i386Ubuntu Ubuntu Linux 10.04 ARMUbuntu Ubuntu Linux 10.04 amd64SuSE SUSE Linux Enterprise Server for VMware 11 SP1+ Linux kernel 2.6.5 SuSE SUSE Linux Enterprise Server 11 SP1SuSE SUSE Linux Enterprise Server 10 SP4SuSE SUSE Linux Enterprise Server 10 SP3 LTSSSuSE SUSE Linux Enterprise SDK 11 SP1SuSE SUSE Linux Enterprise SDK 10 SP4SuSE SUSE Linux Enterprise Desktop 11 SP1+ Linux kernel 2.6.5 SuSE SUSE Linux Enterprise Desktop 10 SP4+ Linux kernel 2.6.5 SuSE openSUSE 11.4SuSE openSUSE 11.3RedHat Enterprise Linux WS 4RedHat Enterprise Linux ES 4RedHat Enterprise Linux Desktop Workstation 5 clientRedHat Enterprise Linux Desktop version 4Red Hat Fedora 16Red Hat Fedora 15Red Hat Enterprise Virtualization Hypervisor for RHEL 6 0Red Hat Enterprise Virtualization Hypervisor for RHEL 5 0Red Hat Enterprise Linux Workstation Optional 6Red Hat Enterprise Linux Workstation 6Red Hat Enterprise Linux Server Optional 6Red Hat Enterprise Linux Server 6Red Hat Enterprise Linux HPC Node Optional 6Red Hat Enterprise Linux HPC Node 6Red Hat Enterprise Linux Desktop Optional 6Red Hat Enterprise Linux Desktop 6Red Hat Enterprise Linux Desktop 5 clientRed Hat Enterprise Linux AS 4Red Hat Enterprise Linux 5 ServerOracle Enterprise Linux 6.2Oracle Enterprise Linux 6Oracle Enterprise Linux 5Oracle Enterprise Linux 4OpenSSL Project OpenSSL 0.9.8 kOpenSSL Project OpenSSL 0.9.8 jOpenSSL Project OpenSSL 0.9.8 iOpenSSL Project OpenSSL 0.9.8 hOpenSSL Project OpenSSL 0.9.8 eOpenSSL Project OpenSSL 0.9.8 dOpenSSL Project OpenSSL 0.9.8 cOpenSSL Project OpenSSL 0.9.8 bOpenSSL Project OpenSSL 0.9.8 aOpenSSL Project OpenSSL 1.0.0eOpenSSL Project OpenSSL 1.0.0dOpenSSL Project OpenSSL 1.0.0cOpenSSL Project OpenSSL 1.0.0bOpenSSL Project OpenSSL 1.0.0bOpenSSL Project OpenSSL 1.0.0bOpenSSL Project OpenSSL 1.0.0aOpenSSL Project OpenSSL 0.9.8ROpenSSL Project OpenSSL 0.9.8QOpenSSL Project OpenSSL 0.9.8pOpenSSL Project OpenSSL 0.9.8pOpenSSL Project OpenSSL 0.9.8oOpenSSL Project OpenSSL 0.9.8OOpenSSL Project OpenSSL 0.9.8NOpenSSL Project OpenSSL 0.9.8nOpenSSL Project OpenSSL 0.9.8mOpenSSL Project OpenSSL 0.9.8MOpenSSL Project OpenSSL 0.9.8lOpenSSL Project OpenSSL 0.9.8gOpenSSL Project OpenSSL 0.9.8fOpenSSL Project OpenSSL 0.9.8 fMandriva Linux Mandrake 2011 x86_64Mandriva Linux Mandrake 2011Mandriva Linux Mandrake 2010.1 x86_64Mandriva Linux Mandrake 2010.1MandrakeSoft Enterprise Server 5 x86_64MandrakeSoft Enterprise Server 5IBM Vios 2.1IBM Vios 2.0IBM Vios 1.5IBM Vios 1.4IBM Vios 1.1IBM AIX 7.1IBM AIX 6.1IBM AIX 5.3IBM AIX 5.2HP SSL for OpenVMS 1.4-453HP SSL for OpenVMS 1.4HP SSL for OpenVMS 1.3HP Onboard Administrator 3.50HP HP-UX B.11.31HP HP-UX B.11.23HP HP-UX B.11.11Gentoo Linux FreeBSD Freebsd 9.0-STABLEFreeBSD Freebsd 9.0-RELEASEFreeBSD Freebsd 8.3-STABLEFreeBSD Freebsd 8.2-STABLEFreeBSD Freebsd 8.2-STABLEFreeBSD Freebsd 8.2FreeBSD Freebsd 8.1FreeBSD Freebsd 7.4-STABLEFreeBSD Freebsd 7.4Debian Linux 6.0 sparcDebian Linux 6.0 s/390Debian Linux 6.0 powerpcDebian Linux 6.0 mipsDebian Linux 6.0 ia-64Debian Linux 6.0 ia-32Debian Linux 6.0 armDebian Linux 6.0 amd64Avaya Voice Portal 5.1.2Avaya Voice Portal 5.1.1Avaya Voice Portal 5.1 SP1Avaya Voice Portal 5.1Avaya Voice Portal 5.1Avaya Voice Portal 5.0 SP2Avaya Voice Portal 5.0 SP1Avaya Voice Portal 5.0Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 5.0Avaya Proactive Contact 4.2.2Avaya Proactive Contact 4.2.1Avaya Proactive Contact 4.2Avaya Proactive Contact 4.1Avaya Proactive Contact 4.0.1Avaya Proactive Contact 4.0Avaya Messaging Storage Server 5.2.8Avaya Messaging Storage Server 5.2.2Avaya Messaging Storage Server 5.2 SP3Avaya Messaging Storage Server 5.2 SP2Avaya Messaging Storage Server 5.2 SP1Avaya Messaging Storage Server 5.2Avaya Messaging Storage Server 5.1 SP2Avaya Messaging Storage Server 5.1 SP1Avaya Messaging Storage Server 5.1Avaya Messaging Storage Server 5.0Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4Avaya Message Networking 5.2.3Avaya Message Networking 5.2.2Avaya Message Networking 5.2 SP1Avaya Message Networking 5.2Avaya Meeting Exchange 5.0 .0.52Avaya Meeting Exchange 5.2 SP2Avaya Meeting Exchange 5.2 SP1Avaya Meeting Exchange 5.2Avaya Meeting Exchange 5.1 SP1Avaya Meeting Exchange 5.1Avaya Meeting Exchange 5.0 SP2Avaya Meeting Exchange 5.0 SP1Avaya Meeting Exchange 5.0Avaya IQ 4.1 Avaya IQ 5.2Avaya IQ 5.1.1Avaya IQ 5.1Avaya IQ 5Avaya IQ 4.2Avaya IQ 4.0Avaya IP Office Application Server 8.0Avaya IP Office Application Server 7.0Avaya IP Office Application Server 6.1Avaya IP Office Application Server 6.0Avaya Communication Server 1000M Signaling Server 7.5Avaya Communication Server 1000M Signaling Server 7.0Avaya Communication Server 1000M 7.5Avaya Communication Server 1000M 7.0Avaya Communication Server 1000E Signaling Server 7.5Avaya Communication Server 1000E Signaling Server 7.0Avaya Communication Server 1000E 7.5Avaya Communication Server 1000E 7.0Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3Avaya Aura System Platform 6.0 SP2Avaya Aura System Platform 6.0Avaya Aura System Platform 1.1Avaya Aura System Manager 6.2Avaya Aura System Manager 6.1.3Avaya Aura System Manager 6.1.2Avaya Aura System Manager 6.1.1Avaya Aura System Manager 6.1 SP2Avaya Aura System Manager 6.1 Sp1Avaya Aura System Manager 6.1Avaya Aura System Manager 6.0 SP1Avaya Aura System Manager 6.0Avaya Aura System Manager 5.2Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2Avaya Aura SIP Enablement Services 5.1Avaya Aura SIP Enablement Services 5.0Avaya Aura SIP Enablement Services 4.0Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2Avaya Aura Session Manager 6.1 SP2Avaya Aura Session Manager 6.1 Sp1Avaya Aura Session Manager 6.1Avaya Aura Session Manager 6.0 SP1Avaya Aura Session Manager 6.0Avaya Aura Session Manager 5.2 SP2Avaya Aura Session Manager 5.2 SP1Avaya Aura Session Manager 5.2Avaya Aura Session Manager 1.1Avaya Aura Session Manager 1.0Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1Avaya Aura Presence Services 6.0Avaya Aura Messaging 6.1+ Avaya Communication Manager Server DEFINITY Server SI/CS + Avaya Communication Manager Server S8100 + Avaya Communication Manager Server S8300 + Avaya Communication Manager Server S8500 + Avaya Communication Manager Server S8700 Avaya Aura Messaging 6.0.1Avaya Aura Messaging 6.0Avaya Aura Experience Portal 6.0Avaya Aura Conferencing 6.0 StandardAvaya Aura Communication Manager Utility Services 6.2Avaya Aura Communication Manager Utility Services 6.1+ Avaya Communication Manager Server DEFINITY Server SI/CS + Avaya Communication Manager Server S8100 + Avaya Communication Manager Server S8300 + Avaya Communication Manager Server S8500 + Avaya Communication Manager Server S8700 Avaya Aura Communication Manager Utility Services 6.0Avaya Aura Communication Manager 6.0.1+ Avaya Communication Manager Server DEFINITY Server SI/CS + Avaya Communication Manager Server S8100 + Avaya Communication Manager Server S8300 + Avaya Communication Manager Server S8500 + Avaya Communication Manager Server S8700 Avaya Aura Communication Manager 6.0Avaya Aura Communication Manager 5.2Avaya Aura Communication Manager 5.1Avaya Aura Communication Manager 4.0Avaya Aura Communication Manager 4.0Avaya Aura Application Server 5300 SIP Core 2.1Avaya Aura Application Server 5300 SIP Core 2.0Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1Avaya Aura Application Enablement Services 6.1Avaya Aura Application Enablement Services 5.2.3Avaya Aura Application Enablement Services 5.2.2Avaya Aura Application Enablement Services 5.2Avaya 96x1 IP Deskphone 6.2Avaya 96x1 IP Deskphone 6Attachmate Reflection for UNIX and OpenVMS 2008 0Attachmate Reflection for IBM 2008 0Attachmate Reflection for IBM 2007 0Attachmate Reflection 14.1 SP1Attachmate Reflection 14.1Attachmate Reflection 14.0 SP1Attachmate Reflection 14.0Not Vulnerable: OpenSSL Project OpenSSL 1.0.0fOpenSSL Project OpenSSL 0.9.8s Quote