DEBIAN-CVE-2011-3389

Advisory lineage Upstream: 1 Downstream: 6
Published: 06 Sept 2011, 19:55
Last modified:28 Apr 2026, 20:07

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Sept 2011, 19:55
Published
Vulnerability first disclosed
28 Apr 2026, 20:07
Last Modified
Vulnerability information updated

Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

Affected Systems

  • debianasterisk

    < 1:13.7.2~dfsg-1

  • debianbouncycastle

    < 1.49+dfsg-1 | < 1.49+dfsg-1 | < 1.49+dfsg-1 | < 1.49+dfsg-1

  • debiancurl

    < 7.24.0-1 | < 7.24.0-1 | < 7.24.0-1 | < 7.24.0-1

  • debianerlang

    < 1:15.b-dfsg-1 | < 1:15.b-dfsg-1 | < 1:15.b-dfsg-1 | < 1:15.b-dfsg-1

  • debiangnutls28

    all | all | all | all

  • debianhaskell-tls

    all | all | all | all

  • debianlighttpd

    < 1.4.30-1 | < 1.4.30-1 | < 1.4.30-1 | < 1.4.30-1

  • debiannss

    < 3.13.1.with.ckbi.1.88-1 | < 3.13.1.with.ckbi.1.88-1 | < 3.13.1.with.ckbi.1.88-1 | < 3.13.1.with.ckbi.1.88-1

  • debianpound

    < 2.6-2 | < 2.6-2 | < 2.6-2

  • debianpython2.7

    < 2.7.3~rc1-1

References (1)