|
OpenSSL contains a flaw related to the use of weak keys in a Diffie-Hellman (DH) key exchange. An OpenSSL server does not exclude weak DH keys sent by a client. This issue, in conjunction with other weaknesses, could lead to a Man-in-The-Middle (MiTM) attack and cause the program to generate a predictable secret.
|