Description
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Slider Widget Cross-Site Scripting (1.8.4)
WordPress Plugin Gravity Forms Directory Cross-Site Scripting (3.7.1)
PHP Other Vulnerability (CVE-2007-1777)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6752)
WordPress Plugin LearnPress-WordPress LMS Multiple Cross-Site Scripting Vulnerabilities (4.1.3)