CVE-2013-0169

CVSS v2.0 2.6 (Low)
26% Progress
EPSS 0.54 % (78th)
0.54% Progress
Affected Products 3
Advisories 45

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-02-08 19:55:01
(11 years ago)
Updated Date
2023-05-12 12:58:44
(16 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Openssl from 0.9.8 version and 0.9.8x and prior versions cpe:2.3:a:openssl:openssl >= 0.9.8 <= 0.9.8x
  Openssl from 1.0.0 version and 1.0.0j and prior versions cpe:2.3:a:openssl:openssl >= 1.0.0 <= 1.0.0j
  Openssl from 1.0.1 version and 1.0.1d and prior versions cpe:2.3:a:openssl:openssl >= 1.0.1 <= 1.0.1d

Configuration #2

    CPE23 From Up To
  Oracle Openjdk 1.6.0 cpe:2.3:a:oracle:openjdk:1.6.0:-
  Oracle Openjdk 1.6.0 Update1 cpe:2.3:a:oracle:openjdk:1.6.0:update1
  Oracle Openjdk 1.6.0 Update10 cpe:2.3:a:oracle:openjdk:1.6.0:update10
  Oracle Openjdk 1.6.0 Update11 cpe:2.3:a:oracle:openjdk:1.6.0:update11
  Oracle Openjdk 1.6.0 Update12 cpe:2.3:a:oracle:openjdk:1.6.0:update12
  Oracle Openjdk 1.6.0 Update13 cpe:2.3:a:oracle:openjdk:1.6.0:update13
  Oracle Openjdk 1.6.0 Update14 cpe:2.3:a:oracle:openjdk:1.6.0:update14
  Oracle Openjdk 1.6.0 Update15 cpe:2.3:a:oracle:openjdk:1.6.0:update15
  Oracle Openjdk 1.6.0 Update16 cpe:2.3:a:oracle:openjdk:1.6.0:update16
  Oracle Openjdk 1.6.0 Update17 cpe:2.3:a:oracle:openjdk:1.6.0:update17
  Oracle Openjdk 1.6.0 Update18 cpe:2.3:a:oracle:openjdk:1.6.0:update18
  Oracle Openjdk 1.6.0 Update19 cpe:2.3:a:oracle:openjdk:1.6.0:update19
  Oracle Openjdk 1.6.0 Update2 cpe:2.3:a:oracle:openjdk:1.6.0:update2
  Oracle Openjdk 1.6.0 Update20 cpe:2.3:a:oracle:openjdk:1.6.0:update20
  Oracle Openjdk 1.6.0 Update21 cpe:2.3:a:oracle:openjdk:1.6.0:update21
  Oracle Openjdk 1.6.0 Update22 cpe:2.3:a:oracle:openjdk:1.6.0:update22
  Oracle Openjdk 1.6.0 Update23 cpe:2.3:a:oracle:openjdk:1.6.0:update23
  Oracle Openjdk 1.6.0 Update24 cpe:2.3:a:oracle:openjdk:1.6.0:update24
  Oracle Openjdk 1.6.0 Update25 cpe:2.3:a:oracle:openjdk:1.6.0:update25
  Oracle Openjdk 1.6.0 Update26 cpe:2.3:a:oracle:openjdk:1.6.0:update26
  Oracle Openjdk 1.6.0 Update27 cpe:2.3:a:oracle:openjdk:1.6.0:update27
  Oracle Openjdk 1.6.0 Update29 cpe:2.3:a:oracle:openjdk:1.6.0:update29
  Oracle Openjdk 1.6.0 Update3 cpe:2.3:a:oracle:openjdk:1.6.0:update3
  Oracle Openjdk 1.6.0 Update30 cpe:2.3:a:oracle:openjdk:1.6.0:update30
  Oracle Openjdk 1.6.0 Update31 cpe:2.3:a:oracle:openjdk:1.6.0:update31
  Oracle Openjdk 1.6.0 Update32 cpe:2.3:a:oracle:openjdk:1.6.0:update32
  Oracle Openjdk 1.6.0 Update33 cpe:2.3:a:oracle:openjdk:1.6.0:update33
  Oracle Openjdk 1.6.0 Update34 cpe:2.3:a:oracle:openjdk:1.6.0:update34
  Oracle Openjdk 1.6.0 Update35 cpe:2.3:a:oracle:openjdk:1.6.0:update35
  Oracle Openjdk 1.6.0 Update37 cpe:2.3:a:oracle:openjdk:1.6.0:update37
  Oracle Openjdk 1.6.0 Update38 cpe:2.3:a:oracle:openjdk:1.6.0:update38
  Oracle Openjdk 1.6.0 Update4 cpe:2.3:a:oracle:openjdk:1.6.0:update4
  Oracle Openjdk 1.6.0 Update5 cpe:2.3:a:oracle:openjdk:1.6.0:update5
  Oracle Openjdk 1.6.0 Update6 cpe:2.3:a:oracle:openjdk:1.6.0:update6
  Oracle Openjdk 1.6.0 Update7 cpe:2.3:a:oracle:openjdk:1.6.0:update7
  Oracle Openjdk 1.7.0 cpe:2.3:a:oracle:openjdk:1.7.0:-
  Oracle Openjdk 1.7.0 Update1 cpe:2.3:a:oracle:openjdk:1.7.0:update1
  Oracle Openjdk 1.7.0 Update10 cpe:2.3:a:oracle:openjdk:1.7.0:update10
  Oracle Openjdk 1.7.0 Update11 cpe:2.3:a:oracle:openjdk:1.7.0:update11
  Oracle Openjdk 1.7.0 Update13 cpe:2.3:a:oracle:openjdk:1.7.0:update13
  Oracle Openjdk 1.7.0 Update2 cpe:2.3:a:oracle:openjdk:1.7.0:update2
  Oracle Openjdk 1.7.0 Update3 cpe:2.3:a:oracle:openjdk:1.7.0:update3
  Oracle Openjdk 1.7.0 Update4 cpe:2.3:a:oracle:openjdk:1.7.0:update4
  Oracle Openjdk 1.7.0 Update5 cpe:2.3:a:oracle:openjdk:1.7.0:update5
  Oracle Openjdk 1.7.0 Update6 cpe:2.3:a:oracle:openjdk:1.7.0:update6
  Oracle Openjdk 1.7.0 Update7 cpe:2.3:a:oracle:openjdk:1.7.0:update7
  Oracle Openjdk 1.7.0 Update9 cpe:2.3:a:oracle:openjdk:1.7.0:update9

Configuration #3

    CPE23 From Up To
  Polarssl 0.10.0 cpe:2.3:a:polarssl:polarssl:0.10.0
  Polarssl 0.10.1 cpe:2.3:a:polarssl:polarssl:0.10.1
  Polarssl 0.11.0 cpe:2.3:a:polarssl:polarssl:0.11.0
  Polarssl 0.11.1 cpe:2.3:a:polarssl:polarssl:0.11.1
  Polarssl 0.12.0 cpe:2.3:a:polarssl:polarssl:0.12.0
  Polarssl 0.12.1 cpe:2.3:a:polarssl:polarssl:0.12.1
  Polarssl 0.13.1 cpe:2.3:a:polarssl:polarssl:0.13.1
  Polarssl 0.14.0 cpe:2.3:a:polarssl:polarssl:0.14.0
  Polarssl 0.14.2 cpe:2.3:a:polarssl:polarssl:0.14.2
  Polarssl 0.14.3 cpe:2.3:a:polarssl:polarssl:0.14.3
  Polarssl 0.99 Pre1 cpe:2.3:a:polarssl:polarssl:0.99:pre1
  Polarssl 0.99 Pre3 cpe:2.3:a:polarssl:polarssl:0.99:pre3
  Polarssl 0.99 Pre4 cpe:2.3:a:polarssl:polarssl:0.99:pre4
  Polarssl 0.99 Pre5 cpe:2.3:a:polarssl:polarssl:0.99:pre5
  Polarssl 1.0.0 cpe:2.3:a:polarssl:polarssl:1.0.0
  Polarssl 1.1.0 cpe:2.3:a:polarssl:polarssl:1.1.0
  Polarssl 1.1.0 Rc0 cpe:2.3:a:polarssl:polarssl:1.1.0:rc0
  Polarssl 1.1.0 Rc1 cpe:2.3:a:polarssl:polarssl:1.1.0:rc1
  Polarssl 1.1.1 cpe:2.3:a:polarssl:polarssl:1.1.1
  Polarssl 1.1.2 cpe:2.3:a:polarssl:polarssl:1.1.2
  Polarssl 1.1.3 cpe:2.3:a:polarssl:polarssl:1.1.3
  Polarssl 1.1.4 cpe:2.3:a:polarssl:polarssl:1.1.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...