PT-2013-3844 · Ietf+1 · Ssl+2

Bertram Poettering

+4

·

Published

2013-03-14

·

Updated

2026-05-22

·

CVE-2013-2566

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TLS protocol (affected versions not specified) SSL protocol (affected versions not specified)
Description The issue concerns the RC4 algorithm used in the TLS and SSL protocols, which contains single-byte biases. This weakness allows remote attackers to potentially recover plaintext through statistical analysis of ciphertext in multiple sessions that utilize the same plaintext.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1150
ALT-PU-2013-1334
ALT-PU-2014-1201
CVE-2013-2566
MGASA-2013-0337

Affected Products

Alt Linux
Ssl
Tls