Package : openssl Vulnerability : cryptographic weakness Problem type : remote Debian-specific: no CVE ID : CVE-2005-2969
Yutaka Oiwa discovered a vulnerability in the Open Secure Socket Layer (OpenSSL) library that can allow an attacker to perform active protocol-version rollback attacks that could lead to the use of the weaker SSL 2.0 protocol even though both ends support SSL 3.0 or TLS 1.0.
The following matrix explains which version in which distribution has this problem corrected.