Detailed Description
A vulnerability has been reported in current versions of SSL and TLS protocols, involving a lack of cryptographic association between original set of security parameters and the one resulting after renegotiation. This condition may allow an attacker to inject data and instructions into the HTTPS connection, triggering unauthorized transactions made under the user's name.