smtp service vulnerable to POODLE SSLv3
Low
M
MariaDB
Submitted None
Team Summary
Official summary from MariaDB
One of our package servers had an old smtpd service linked with openssl 1.0.1i, which uses nondeterministic CBC padding, making it easy for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. The service has been disabled for the internet, as it was not necessary to begin with.
Actions:
Reported by
rudrahacks007
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cryptographic Issues - Generic