Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2061

Опубликовано: 18 нояб. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.6

Описание

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

РелизСтатусПримечание
devel

not-affected

2.3.1-2ubuntu1
esm-infra-legacy/trusty

not-affected

2.3.1-2ubuntu1
hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

released

2.2.1-8ubuntu1.3
quantal

ignored

end of life
raring

ignored

end of life
saucy

not-affected

2.3.1-2ubuntu1
trusty

not-affected

2.3.1-2ubuntu1

Показывать по

EPSS

Процентиль: 80%
0.0145
Низкий

2.6 Low

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

debian
больше 11 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, ...

github
около 3 лет назад

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

fstec
больше 11 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации

EPSS

Процентиль: 80%
0.0145
Низкий

2.6 Low

CVSS2