CVE-2013-1620
nss: TLS CBC padding timing attack
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
La implementación en Mozilla Network Security Services (NSS) de TLS no tiene debidamente en cuenta tiempos de canal lateral ataques a una operación de comprobación de incumplimiento MAC durante el procesamiento de malformaciones relleno CBC, que permite a atacantes remotos para realizar ataques distintivos y los ataques de recuperación de texto plano-a través de análisis estadístico de datos de tiempo de los paquetes hechos a mano, una cuestión relacionada con CVE-2013-0169.
Google reported to Mozilla that TURKTRUST, a certificate authority in Mozillas root program, had mis-issued two intermediate certificates to customers. The issue was not specific to Firefox but there was evidence that one of the certificates was used for man-in-the-middle traffic management of domain names that the customer did not legitimately own or control. This issue was resolved by revoking the trust for these specific mis-issued certificates. The rootcerts package has been upgraded to address this flaw and the Mozilla NSS package has been rebuilt to pickup the changes. The TLS implementation in Mozilla Network Security Services does not properly consider timing side-channel attacks on a non-compliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169. The NSPR package has been upgraded to the 4.9.5 version due to dependencies of newer NSS. The NSS package has been upgraded to the 3.14.3 version which is not vulnerable to this issue. The sqlite3 update addresses a crash when using svn commit after export MALLOC_CHECK_=3.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-05 CVE Reserved
- 2013-02-08 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
CAPEC
References (21)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html | 2022-12-21 | |
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html | 2022-12-21 | |
http://rhn.redhat.com/errata/RHSA-2013-1135.html | 2022-12-21 | |
http://rhn.redhat.com/errata/RHSA-2013-1144.html | 2022-12-21 | |
http://security.gentoo.org/glsa/glsa-201406-19.xml | 2022-12-21 | |
http://www.ubuntu.com/usn/USN-1763-1 | 2022-12-21 | |
https://access.redhat.com/security/cve/CVE-2013-1620 | 2013-08-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=908234 | 2013-08-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Network Security Services Search vendor "Mozilla" for product "Network Security Services" | < 3.14.3 Search vendor "Mozilla" for product "Network Security Services" and version " < 3.14.3" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 11.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "11.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 11.1 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "11.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.1 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Manager Ops Center Search vendor "Oracle" for product "Enterprise Manager Ops Center" | 12.2 Search vendor "Oracle" for product "Enterprise Manager Ops Center" and version "12.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Glassfish Communications Server Search vendor "Oracle" for product "Glassfish Communications Server" | 2.0 Search vendor "Oracle" for product "Glassfish Communications Server" and version "2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Glassfish Server Search vendor "Oracle" for product "Glassfish Server" | 2.1.1 Search vendor "Oracle" for product "Glassfish Server" and version "2.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Iplanet Web Proxy Server Search vendor "Oracle" for product "Iplanet Web Proxy Server" | 4.0 Search vendor "Oracle" for product "Iplanet Web Proxy Server" and version "4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Iplanet Web Server Search vendor "Oracle" for product "Iplanet Web Server" | 6.1 Search vendor "Oracle" for product "Iplanet Web Server" and version "6.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Iplanet Web Server Search vendor "Oracle" for product "Iplanet Web Server" | 7.0 Search vendor "Oracle" for product "Iplanet Web Server" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Opensso Search vendor "Oracle" for product "Opensso" | 3.0-03 Search vendor "Oracle" for product "Opensso" and version "3.0-03" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Traffic Director Search vendor "Oracle" for product "Traffic Director" | 11.1.1.6.0 Search vendor "Oracle" for product "Traffic Director" and version "11.1.1.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Traffic Director Search vendor "Oracle" for product "Traffic Director" | 11.1.1.7.0 Search vendor "Oracle" for product "Traffic Director" and version "11.1.1.7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.2 Search vendor "Oracle" for product "Vm Server" and version "3.2" | x86 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 5.9 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "5.9" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 5.9 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "5.9" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 5.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "5.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|