Impact
Does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
To be able to interop with Google servers a CBC padding check was removed and add back when the POODLE attack was discovered and the Google servers fixed.
Workarounds
Do not use TLS-1.0
Affected/Unaffected Versions
A version larger than or equal to one of the listed patched versions is unaffected; otherwise, a version that satisfies an expression listed under affected versions is affected, and if it does not, it is unaffected.
The documentation of the new OTP version scheme describes how versions should be compared. Note that versions used prior to OTP 17.0, when the new OTP version scheme was introduced, are never listed since it is not well defined how to compare those versions.
This particular vulnerability exist in versions older then OTP 17.0 but not prior to ssl application version 4.0.1
Impact
Does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
To be able to interop with Google servers a CBC padding check was removed and add back when the POODLE attack was discovered and the Google servers fixed.
Workarounds
Do not use TLS-1.0
Affected/Unaffected Versions
A version larger than or equal to one of the listed patched versions is unaffected; otherwise, a version that satisfies an expression listed under affected versions is affected, and if it does not, it is unaffected.
The documentation of the new OTP version scheme describes how versions should be compared. Note that versions used prior to OTP 17.0, when the new OTP version scheme was introduced, are never listed since it is not well defined how to compare those versions.
This particular vulnerability exist in versions older then OTP 17.0 but not prior to ssl application version 4.0.1