Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dan Bernstein

#51383of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2013-3844
4.3
2013-03-14
Ietf · Ssl · CVE-2013-2566
**Name of the Vulnerable Software and Affected Versions** TLS protocol (affected versions not specified) SSL protocol (affected versions not specified) **Description** The issue concerns the RC4 algorithm used in the TLS and SSL protocols, which contains single-byte biases. This weakness allows remote attackers to potentially recover plaintext through statistical analysis of ciphertext in multiple sessions that utilize the same plaintext. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.