CVE-2015-4000: Apple iPhone OS
Low severity, CVSS 3.7. EPSS: 99.9% chance of exploitation in the next 30 days.
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Affected products
- Apple iPhone OS: up to and including 8.3
- Apple Mac OS X: up to and including 10.10.3
- Apple Safari: affected versions not specified
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Google Chrome: affected versions not specified
- HP HP-Ux: version b.11.31 only
- IBM Content Manager: version 8.5 only
- Microsoft Internet Explorer: affected versions not specified
- Mozilla Firefox: affected versions not specified; version 38.1.0 only; version 39.0 only
- Mozilla Firefox ESR: version 31.8 only
- Mozilla Firefox OS: version 2.2 only
- Mozilla Network Security Services: version 3.19 only
- Mozilla Seamonkey: version 2.35 only
- Mozilla Thunderbird: version 31.8 only; version 38.1 only
- OpenSSL OpenSSL: from 1.0.1, up to and including 1.0.1m; from 1.0.2, up to and including 1.0.2a; up to and including 1.0.1m
- Opera Opera Browser: affected versions not specified
- Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
- Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
- Oracle JRockit: version r28.3.6 only
- Oracle Sparc-Opl Service Processor: up to and including 1121
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Server: version 11.0 only
- Suse Linux Enterprise Software Development Kit: version 12 only
- Suse Suse Linux Enterprise Server: version 12 only
Published 2015-05-21. Last modified 2026-06-17.