CVE-2013-1619
published 2013-02-08CVE-2013-1619: The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a…
PriorityP425medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
6.44%
93.0th percentile
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Affected
119 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.0.22-3 (bookworm) | gnutls28 3.0.22-3 (bookworm) |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2013-02-27
CVE-2013-1619 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to expose sensitive information over the network.
Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used
in GnuTLS was vulnerable to a timing side-channel attack known as the
"Lucky Thirteen" issue. A remote attacker could use this issue to perform
plaintext-recovery attacks via analysis of timing data.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: TLS CBC padding timing attack (lucky-13)
vendor_redhat·2013-02-04·CVSS 2.6
CVE-2013-1619 [LOW] gnutls: TLS CBC padding timing attack (lucky-13)
gnutls: TLS CBC padding timing attack (lucky-13)
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2013-1619: gnutls28 - The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x ...
vendor_debian·2013·CVSS 2.6
CVE-2013-1619 [LOW] CVE-2013-1619: gnutls28 - The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x ...
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Scope: local
bookworm: resolved (fixed in 3.0.22-3)
bullseye: resolved (fixed in 3.0.22-3)
forky: resolved (fixed in 3.0.22-3)
sid: resolved (fixed in 3.0.22-3)
trixie: resolved (fixed in 3.0.22-3)
GHSA
GHSA-qmwj-552p-59h4: The TLS implementation in GnuTLS before 2
ghsa_unreviewed·2022-05-17·CVSS 2.6
CVE-2013-1619 [LOW] GHSA-qmwj-552p-59h4: The TLS implementation in GnuTLS before 2
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
OSV
CVE-2013-1619: The TLS implementation in GnuTLS before 2
osv·2013-02-08·CVSS 2.6
CVE-2013-1619 [LOW] CVE-2013-1619: The TLS implementation in GnuTLS before 2
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8313 gnutls: First byte of the padding in CBC mode is not checked
bugzilla·2015-12-02·CVSS 4.0
CVE-2015-8313 [MEDIUM] CVE-2015-8313 gnutls: First byte of the padding in CBC mode is not checked
CVE-2015-8313 gnutls: First byte of the padding in CBC mode is not checked
It was discovered that gnutls incorrectly validates the first byte of padding in CBC modes. A remote attacker can possibly take advantage of this flaw to perform a padding oracle attack. Affected are older versions of gnutls (2.x).
Public via:
https://www.debian.org/security/2015/dsa-3408
http://seclists.org/bugtraq/2015/Dec/0
Discussion:
This bug does not affect RHEL-6 or RHEL-7. They have been patched with the proper fixes for Lucky13 which included the fix for that issue.
---
It doesn't affect RHEL-5 either.
---
Details of this issue can be found in the Hanno Böck's blog post:
https://blog.hboeck.de/archives/877-A-little-POODLE-left-in-GnuTLS-old-versions.html
Here is also the original Ubuntu bug repor
Bugzilla
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
bugzilla·2013-05-23·CVSS 4.0
CVE-2013-2116 [MEDIUM] CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
A flaw was found in the way GnuTLS decrypted TLS record packets when using CBC encryption. The number of pad bytes read form the packet was not checked against the cipher text size, resulting in an out of bounds read. This could cause a TLS client or server using GnuTLS to crash.
This problem was introduced by a fix for Lucky 13 issue CVE-2013-1619, released in Red Hat Enterprise Linux 5 and 6 via RHSA-2013:0588:
https://rhn.redhat.com/errata/RHSA-2013-0588.html
This issue did not affect GnuTLS 3.x which used different patch for Lucky 13, only patch for 2.x, which did not implement all protections to avoid leak of timing information, contains this bug.
Issue was reported on upstream mailing lis
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-18]
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-18]
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for mingw-gnutls:
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack (lucky-13)
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack (lucky-13)
CVE-2013-1619 gnutls: TLS CBC padding timing attack (lucky-13)
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
The paper indicates that with
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-17]
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-17]
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-17 tracking bug for mingw-gnutls:
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack [epel-5]
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack [epel-5]
CVE-2013-1619 gnutls: TLS CBC padding timing attack [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mingw32-gnutls:
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-16]
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-16]
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-16 tracking bug for mingw32-gnutls
Bugzilla
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-all]
bugzilla·2013-02-05·CVSS 4.0
CVE-2013-1619 [MEDIUM] CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-all]
CVE-2013-1619 gnutls: TLS CBC padding timing attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple
Bugzilla
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
bugzilla·2013-02-04·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
The paper indicates that with Ope
Bugzilla
CVE-2012-6107 axis2c: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
bugzilla·2013-01-11·CVSS 4.3
CVE-2012-6107 [MEDIUM] CVE-2012-6107 axis2c: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
CVE-2012-6107 axis2c: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate
Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Upstream bug report:
[1] https://issues.apache.org/jira/browse/AXIS2C-1619
References:
[2] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
[3] http://www.openwall.com/lists/oss-security/2013/01/11/4
[4] http://mail-archives.apache.org/mod_mbox/axis-c-dev/201301.mbox/browser
[5] http://www.openwall.com/lists/oss-security/2013/01/11/8
Discussion:
This issue affects the version of
arXiv
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
arxiv_fulltext·2019-12-12
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
Revisiting and Evaluating Software Side-channel Vulnerabilities and Countermeasures in Cryptographic Applications
Tianwei Zhang
Nanyang Technological University
[email protected]
Jun Jiang
Two Sigma Investments, LP
[email protected]
Yinqian Zhang
The Ohio State University
[email protected]
dkgreenrgb0,0.6,0
grayrgb0.5,0.5,0.5
mauvergb0.58,0,0.82
frame=tb,
language=C,
aboveskip=3mm,
belowskip=3mm,
showstringspaces=false,
columns=flexible,
basicstyle= ,
numbers=left,
numbersep=-2pt,
numberstyle= ,
keywordstyle=blue,
commentstyle=dkgreen,
stringstyle=mauve,
breaklines=true,
breakatwhitespace=true,
tabsize=3
## Abstract
We systematize software side-channel attacks with a focus on vulnerabilities
and countermeasures in the cryptographic implementations. Particularly,
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00023.htmlhttp://nmav.gnutls.org/2013/02/time-is-money-for-cbc-ciphersuites.htmlhttp://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2013-0588.htmlhttp://secunia.com/advisories/57260http://secunia.com/advisories/57274http://www.gnutls.org/security.html#GNUTLS-SA-2013-1http://www.isg.rhul.ac.uk/tls/TLStiming.pdfhttp://www.ubuntu.com/usn/USN-1752-1https://gitorious.org/gnutls/gnutls/commit/328ee22c1b3951e060c7124c7cb1cee592c59bc0https://gitorious.org/gnutls/gnutls/commit/b8391806cd79095fe566f2401d8c7ad85a64b198http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00023.htmlhttp://nmav.gnutls.org/2013/02/time-is-money-for-cbc-ciphersuites.htmlhttp://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2013-0588.htmlhttp://secunia.com/advisories/57260http://secunia.com/advisories/57274http://www.gnutls.org/security.html#GNUTLS-SA-2013-1http://www.isg.rhul.ac.uk/tls/TLStiming.pdfhttp://www.ubuntu.com/usn/USN-1752-1https://gitorious.org/gnutls/gnutls/commit/328ee22c1b3951e060c7124c7cb1cee592c59bc0https://gitorious.org/gnutls/gnutls/commit/b8391806cd79095fe566f2401d8c7ad85a64b198
2013-02-08
Published