Web Hack List

Later archive addition

TLS Renegotiation authentication gap (CVE-2009-3555)

CERT note for CVE-2009-3555, the SSL and TLS renegotiation authentication gap. A man in the middle completes its own handshake, sends chosen plaintext, then relays the client's handshake as a renegotiation, so the server attributes the injected prefix to the client. Affects SSL 3.0 and TLS 1.0 and later; 111 vendors were notified.

Record

Researcher
Chris Taschner

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Taschner, first published at the original source. Preserved copies are kept so the citation survives its host.