Your browser is still vulnerable to Logjam

Currently, only Internet Explorer is safe from the Logjam vulnerability.

How to: Secure Chrome against Logjam

How to: Secure Firefox against Logjam

Browser/OS Windows OS X iOS Android
IE 11 Safe
(5/20/15 CW)
Safari Vulnerable
(5/20/15 CW)
Vulnerable
(5/20/15 CW)
Chrome 43 Vulnerable
(5/25/15 SOT)
Vulnerable
(5/20/15 CW)
Vulnerable
(5/20/15 CW)
Vulnerable
(5/20/15 CW)
Firefox 38 Vulnerable
(5/30/15 SOT)
Vulnerable
(5/20/15 CW)
Vulnerable
(5/20/15 CW)
Android browser Vulnerable
(5/20/15 CW)

This article builds upon the information in the Computerworld (CW) article published 5/20/15

Test your client (browser):

Patches / Safe Versions

5/12/15 – Microsoft patched IE 11 see MS15-055

5/22/15 – Mozilla released the “Disable DHE” add-on that “disables ephemeral Diffie-Hellman cipher suites that are vulnerable to the logjam attack” for Firefox versions 20.0 – 38.*

 

SOT Testing

5/25/15 – Firefox 38.0.1

20150525-firefox-38-0-1-up-to-date

20150525-ssllabs.com-ssl-client-test-logjam-firefox-38-vulnerable

2015052-ssllabs.com-manual-tetst-firefox-38-vulnerable

5/30/15 – Firefox 38.0.1 no updated release – still vulnerable

Additional information

Schannel – Secure Channel