CVE-2013-0169

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
08/02/2013
Last modified:
11/04/2025

Description

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 0.9.8 (including) 0.9.8x (including)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.0j (including)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 1.0.1 (including) 1.0.1d (including)
cpe:2.3:a:oracle:openjdk:1.6.0:-:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update1:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update11:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update12:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update13:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update14:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update15:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update16:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update17:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update18:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.6.0:update19:*:*:*:*:*:*


References to Advisories, Solutions, and Tools