Loading HuntDB...

smtp service vulnerable to POODLE SSLv3

Low
M
MariaDB
Submitted None

Team Summary

Official summary from MariaDB

One of our package servers had an old smtpd service linked with openssl 1.0.1i, which uses nondeterministic CBC padding, making it easy for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. The service has been disabled for the internet, as it was not necessary to begin with.

Reported by rudrahacks007

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cryptographic Issues - Generic