Nadhem Alfardan

#19398of 53,779
13.6Total CVSS
Vulnerabilities · 3
Medium
3
PT-2013-3282
4.3
2013-02-08
Oracle · Oracle Vm Server · CVE-2013-1620
**Name of the Vulnerable Software and Affected Versions** Mozilla Network Security Services (NSS) (affected versions not specified) Canonical Ubuntu Linux (affected versions not specified) Oracle Enterprise Manager Ops Center (affected versions not specified) Oracle GlassFish Communications Server (affected versions not specified) Oracle GlassFish Server (affected versions not specified) Oracle iPlanet Web Proxy Server (affected versions not specified) Oracle iPlanet Web Server (affected versions not specified) Oracle OpenSSO (affected versions not specified) Oracle Traffic Director (affected versions not specified) Oracle VM Server (affected versions not specified) Red Hat Enterprise Linux Desktop (affected versions not specified) Red Hat Enterprise Linux EUS (affected versions not specified) Red Hat Enterprise Linux Server (affected versions not specified) Red Hat Enterprise Linux Server AUS (affected versions not specified) Red Hat Enterprise Linux Workstation (affected versions not specified) **Description** The TLS implementation in Mozilla Network Security Services (NSS) is susceptible to timing side-channel attacks due to improper handling of noncompliant MAC check operations during the processing of malformed CBC padding. This allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.