UBUNTU-CVE-2013-0169
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-0169
UBUNTU-CVE-2013-0169
Summary:
Details: The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
References: https://ubuntu.com/security/CVE-2013-0169, http://www.openssl.org/news/secadv_20130204.txt, http://www.isg.rhul.ac.uk/tls/, http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html, https://ubuntu.com/security/notices/USN-1732-1, https://ubuntu.com/security/notices/USN-1735-1, https://ubuntu.com/security/notices/USN-1732-3, https://www.cve.org/CVERecord?id=CVE-2013-0169
Affected packages
Package
Name: openssl098
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
