Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0169

Опубликовано: 08 фев. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6

Описание

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

РелизСтатусПримечание
devel

released

6b27-1.12.3-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [6b27-1.12.3-1ubuntu1]]
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
lucid

released

6b27-1.12.3-0ubuntu1~10.04
oneiric

released

6b27-1.12.3-0ubuntu1~11.10
precise

released

6b27-1.12.3-0ubuntu1~12.04
quantal

released

6b27-1.12.3-0ubuntu1~12.10
raring

released

6b27-1.12.3-1ubuntu1
saucy

released

6b27-1.12.3-1ubuntu1
trusty

released

6b27-1.12.3-1ubuntu1

Показывать по

РелизСтатусПримечание
devel

released

7u15-2.3.7-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [7u15-2.3.7-1ubuntu1]]
hardy

DNE

lucid

DNE

oneiric

released

7u15-2.3.7-0ubuntu1~11.10
precise

released

7u15-2.3.7-0ubuntu1~12.04
quantal

released

7u15-2.3.7-0ubuntu1~12.10
raring

released

7u15-2.3.7-1ubuntu1
saucy

released

7u15-2.3.7-1ubuntu1
trusty

released

7u15-2.3.7-1ubuntu1

Показывать по

РелизСтатусПримечание
devel

released

1.0.1c-4ubuntu8
esm-infra-legacy/trusty

not-affected

1.0.1c-4ubuntu8
hardy

released

0.9.8g-4ubuntu3.20
lucid

released

0.9.8k-7ubuntu8.14
oneiric

released

1.0.0e-2ubuntu4.7
precise

released

1.0.1-4ubuntu5.8
quantal

released

1.0.1c-3ubuntu2.3
raring

released

1.0.1c-4ubuntu8
saucy

released

1.0.1c-4ubuntu8
trusty

released

1.0.1c-4ubuntu8

Показывать по

РелизСтатусПримечание
devel

released

0.9.8o-7ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.9.8o-7ubuntu3.2.14.04.1]]
hardy

DNE

lucid

DNE

oneiric

ignored

end of life
precise

released

0.9.8o-7ubuntu3.2
quantal

ignored

end of life
raring

ignored

end of life
saucy

released

0.9.8o-7ubuntu3.2.13.10.1
trusty

released

0.9.8o-7ubuntu3.2.14.04.1

Показывать по

EPSS

Процентиль: 76%
0.01022
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

nvd
больше 12 лет назад

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

debian
больше 12 лет назад

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as use ...

github
около 3 лет назад

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

oracle-oval
больше 12 лет назад

ELSA-2013-0274: java-1.6.0-openjdk security update (IMPORTANT)

EPSS

Процентиль: 76%
0.01022
Низкий

2.6 Low

CVSS2