CVE-2013-0169
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 35.58% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- openssl/openssl · oracle/openjdk · polarssl/polarssl
- Source
- secalert@redhat.com
References
- http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/Third Party Advisory
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=136396549913849&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136432043316835&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136439120408139&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=136733161405818&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=137545771702053&w=2Third Party Advisory
- http://openwall.com/lists/oss-security/2013/02/05/24Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-0587.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0782.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0783.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0833.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1456.htmlThird Party Advisory
- http://secunia.com/advisories/53623Third Party Advisory
- http://secunia.com/advisories/55108Third Party Advisory
- http://secunia.com/advisories/55139Third Party Advisory
- http://secunia.com/advisories/55322Third Party Advisory
- http://secunia.com/advisories/55350Third Party Advisory
- http://secunia.com/advisories/55351Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://support.apple.com/kb/HT5880Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.