POODLE

lore

cryptographysecurity

A 2014 attack that forces a downgrade to SSL 3.0 to exploit its broken CBC padding.

Padding Oracle On Downgraded Legacy Encryption abused the fact that a client would fall back to SSL 3.0, whose padding could be probed byte by byte to recover data. It effectively ended SSL 3.0 in the field.

Also known as: POODLE, Padding Oracle On Downgraded Legacy Encryption, CVE-2014-3566

Sources

  • CVE-2014-3566 (2014)

All glossary entries