CVE-2015-2808: Canonical Ubuntu Linux
Low severity, CVSS 3.7. EPSS: 73.9% chance of exploitation in the next 30 days.
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fujitsu Sparc Enterprise m3000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
- Fujitsu Sparc Enterprise m4000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
- Fujitsu Sparc Enterprise m5000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
- Fujitsu Sparc Enterprise m8000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
- Fujitsu Sparc Enterprise m9000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
- Huawei 9700 Firmware: affected versions not specified
- Huawei e6000 Firmware: affected versions not specified
- Huawei e9000 Firmware: affected versions not specified
- Huawei Oceanstor 18500 Firmware: affected versions not specified
- Huawei Oceanstor 18800 Firmware: affected versions not specified
- Huawei Oceanstor 18800f Firmware: affected versions not specified
- Huawei Oceanstor 9000 Firmware: affected versions not specified
- Huawei Oceanstor Cse Firmware: affected versions not specified
- Huawei Oceanstor HVS85T Firmware: affected versions not specified
- Huawei Oceanstor Replicationdirector: version v100r003c00 only
- Huawei Oceanstor s2600t Firmware: affected versions not specified
- Huawei Oceanstor s5500t Firmware: affected versions not specified
- Huawei Oceanstor s5600t Firmware: affected versions not specified
- Huawei Oceanstor s5800t Firmware: affected versions not specified
- Huawei Oceanstor s6800t Firmware: affected versions not specified
- Huawei Oceanstor VIS6600T Firmware: affected versions not specified
- Huawei Policy Center: version v100r003c00 only; version v100r003c10 only
- Huawei Quidway s9300 Firmware: affected versions not specified
- and 36 more
Published 2015-04-01. Last modified 2026-06-17.