Web Hack List

Collected research

TLS Renegotiation authentication gap (CVE-2009-3555)

CERT/CC Vulnerability Note VU#120541

CERT note for CVE-2009-3555, the SSL and TLS renegotiation authentication gap. A man in the middle completes its own handshake, sends chosen plaintext, then relays the client's handshake as a renegotiation, so the server attributes the injected prefix to the client. Affects SSL 3.0 and TLS 1.0 and later; 111 vendors were notified.

Record

Document
CERT/CC Vulnerability Note VU#120541
Researcher
Chris Taschner
Published by
kb.cert.org
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Taschner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .