CVE-2013-1619
EPSS 6.4%
描述
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
如何修補 CVE-2013-1619
要修補 CVE-2013-1619,請將受影響套件升級到下列已修補版本。
- Debian/gnutls28—升級至 3.0.22-3 或更新版本
CVE-2013-1619 正在被利用嗎?
中等 — EPSS 為 6.4%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 3.0.22-3