DROWN

lore

cryptographysecurity

A 2016 attack that breaks TLS by exploiting a server's support for obsolete SSLv2.

Decrypting RSA with Obsolete and Weakened eNcryption used a still-enabled SSLv2 endpoint sharing the same RSA key as a cross-protocol oracle to decrypt modern TLS sessions. The lesson was to fully disable SSLv2 everywhere a key is used.

Also known as: DROWN, Decrypting RSA with Obsolete and Weakened eNcryption, CVE-2016-0800

Sources

  • CVE-2016-0800 (2016)

All glossary entries