CVE-2013-0169
polarssl - several
EPSS 35.6%
描述
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
如何修補 CVE-2013-0169
要修補 CVE-2013-0169,請將受影響套件升級到下列已修補版本。
- Debian/bouncycastle—升級至 1.48+dfsg-2 或更新版本
- —升級至 3.0.22-3 或更新版本
- —升級至 2:3.14.3-1 或更新版本
- —升級至 1.0.1e-1 或更新版本
- —升級至 0.12.1-1squeeze1 或更新版本
CVE-2013-0169 正在被利用嗎?
中等 — EPSS 為 35.6%,可持續追蹤但非最高優先。
受影響套件(5)
- from 0, < 1.48+dfsg-2
- from 0, < 3.0.22-3
- from 0, < 2:3.14.3-1
- from 0, < 1.0.1e-1
- from 0, < 0.12.1-1squeeze1