PT-2013-1213 · Oracle+6 · Openjdk+8

Adam Langley

+1

·

Published

1999-01-01

·

Updated

2025-05-12

·

CVE-2013-0169

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.3.0 OpenJDK versions prior to 1.3.0 PolarSSL versions prior to 1.3.0
Description The issue concerns the TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, which do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding. This allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, also known as the "Lucky Thirteen" issue.
Recommendations For OpenSSL versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. For OpenJDK versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. For PolarSSL versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable protocols until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09702
CESA-2013_0273
CESA-2013_0275
CESA-2013_0587
CVE-2013-0169
DLA-1518-1
DSA-2621-1
DSA-2622-1
HPSBUX02856
HPSBUX02857
HPSBUX02909
LOWSTRENGTHCIPHERSUITESCHECK
MGASA-2013-0290
OPENSUSE-SU-2013_0375-1
OPENSUSE-SU-2013_0378-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:10534-1
OPENSUSE-SU-2024:11127-1
RHSA-2013:0273
RHSA-2013:0274
RHSA-2013:0275
RHSA-2013:0531
RHSA-2013:0532
RHSA-2013:0587
RHSA-2013:0636
RHSA-2013:0822
RHSA-2013:0823
RHSA-2013:0855
RHSA-2013:1455
RHSA-2013:1456
RHSA-2013_0273
RHSA-2013_0274
RHSA-2013_0275
RHSA-2013_0531
RHSA-2013_0532
RHSA-2013_0587
RHSA-2013_0822
RHSA-2013_0823
RHSA-2013_0855
RHSA-2014:0416
SUSE-FU-2022:0445-1
SUSE-SU-2013_0701-1
SUSE-SU-2013_0701-2
SUSE-SU-2015:0182-2
SUSE-SU-2015:0344-1
SUSE-SU-2015:0392-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:1086-1
SUSE-SU-2015:1086-3
SUSE-SU-2015:1183-1
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-403
USN-1732-1
USN-1732-3
USN-1735-1

Affected Products

Centos
Hp-Ux
Ibm Aix
Java Platform
Openjdk
Openssl
Polarssl
Red Hat
Suse