Microsoft XML Core Services 3.0, 5.0, and 6.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2434.
| Software | From | Fixed in |
|---|---|---|
| microsoft / xml_core_services | 3.0 | 3.0.x |
| microsoft / xml_core_services | 5.0 | 5.0.x |
| microsoft / xml_core_services | 6.0 | 6.0.x |