Skip to content

Stop recommending DHE, because of "dheater" vulnerability :CVE-2002-20001  #17374

@stardrift1

Description

@stardrift1

These guys found a way to saturate the server CPU core to 100% using as little as 5 KB/s of incoming traffic. The pre-requisite is that the server supports DHE as the key exchange. Therefore, to avoid creating such a vulnerable configuration, I propose removing DHE from the SSL_DEFAULT_CIPHER_LIST or TLS_DEFAULT_CIPHERSUITES.

Metadata

Metadata

Assignees

No one assigned

    Labels

    hold: discussionThe community needs to establish a consensus how to move forward with the issue or PRtriaged: questionThe issue contains a question

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions