Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-14976

[3.0.5 backport] - Remove support for SSL v3 in memcached SSL server sockets to mitigate against the POODLE attack

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 3.1.0
    • 2.5.1, 3.0, 3.0.2
    • memcached
    • Security Level: Public
    • None
    • Untriaged
    • Release Note
    • No

    Description

      Poodle attack described here: http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html

      More user friendly description here: http://blog.cryptographyengineering.com/2014/10/attack-of-week-poodle.html

      My thinking is we currently fix this for 3.0.1 and then create an MB to backport to 2.5.2 whenever that ships.

      Suggested fix: remove SSL v3 support in the versions the server SSL socket supports.

      Attachments

        Issue Links

          No reviews matched the request. Check your Options in the drop-down menu of this sections header.

          Activity

            People

              trond Trond Norbye
              dfinlay Dave Finlay
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Gerrit Reviews

                  There are no open Gerrit changes

                  PagerDuty