CVE-2013-1620
published 2013-02-08CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.72%
88.6th percentile
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nss | < nss 2:3.14.3-1 (bookworm) | nss 2:3.14.3-1 (bookworm) |
| mozilla | network_security_services | < 3.14.3 | 3.14.3 |
| mozilla | nss | >= 0 < 2:3.14.3-1 | 2:3.14.3-1 |
| mozilla | nss | >= 0 < 2:3.14.3-1 | 2:3.14.3-1 |
| mozilla | nss | >= 0 < 2:3.14.3-1 | 2:3.14.3-1 |
| mozilla | nss | >= 0 < 2:3.14.3-1 | 2:3.14.3-1 |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | glassfish_communications_server | — | — |
| oracle | glassfish_server | — | — |
| oracle | iplanet_web_proxy_server | — | — |
| oracle | iplanet_web_server | — | — |
| oracle | iplanet_web_server | — | — |
| oracle | opensso | — | — |
| oracle | traffic_director | — | — |
| oracle | traffic_director | — | — |
| oracle | vm_server | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pp6-m86c-j4gj: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check o
ghsa_unreviewed·2022-05-14·CVSS 2.6
CVE-2013-1620 [LOW] CWE-203 GHSA-4pp6-m86c-j4gj: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check o
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
OSV
CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check o
osv·2013-02-08·CVSS 2.6
CVE-2013-1620 [LOW] CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check o
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
VMware
VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
vendor_vmware·2013-12-03·CVSS 7.9
CVE-2013-0791 [HIGH] VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
VMSA-2013-0014: VMware Workstation, Fusion, ESXi and ESX patches address a guest privilege escalation
a. VMware LGTOSYNC privilege escalation. VMware ESX, Workstation and Fusion contain a vulnerability in the handling of control code in lgtosync.sys. A local malicious user may exploit this vulnerability to manipulate the memory allocation. This could result in a privilege escalation on 32-bit Guest Operating Systems running Windows 2000 Server, Windows XP or Windows 2003 Server on ESXi and ESX; or Windows XP on Workstation and Fusion. The vulnerability does not allow for privilege escalation from the Guest Operating System to the host. This means that host memory can not be manipulated from the Guest Operating System. VMware would like to thank Derek Soeder of Cylance, Inc. for reporting
Ubuntu
NSS vulnerability
vendor_ubuntu·2013-03-14
CVE-2013-1620 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to expose sensitive information over the network.
Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used
in NSS was vulnerable to a timing side-channel attack known as the
"Lucky Thirteen" issue. A remote attacker could use this issue to perform
plaintext-recovery attacks via analysis of timing data.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Red Hat
nss: TLS CBC padding timing attack
vendor_redhat·2013-02-04·CVSS 2.6
CVE-2013-1620 [LOW] nss: TLS CBC padding timing attack
nss: TLS CBC padding timing attack
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Debian
CVE-2013-1620: nss - The TLS implementation in Mozilla Network Security Services (NSS) does not prope...
vendor_debian·2013·CVSS 2.6
CVE-2013-1620 [LOW] CVE-2013-1620: nss - The TLS implementation in Mozilla Network Security Services (NSS) does not prope...
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Scope: local
bookworm: resolved (fixed in 2:3.14.3-1)
bullseye: resolved (fixed in 2:3.14.3-1)
forky: resolved (fixed in 2:3.14.3-1)
sid: resolved (fixed in 2:3.14.3-1)
trixie: resolved (fixed in 2:3.14.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
bugzilla·2013-09-27·CVSS 4.3
CVE-2013-1739 [MEDIUM] CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
A flaw was found in the way nss read uninitialized data, when there was a decryption failure. A remote attacker could use this flaw to cause denial of service for applications linked with the nss library (application crash)
The vulnerable code was added in NSS 3.14.3 to fix the lucky-13 issue (CVE-2013-1620). This issue is resolved in nss-3.15.2
References:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_notes
https://bugzilla.mozilla.org/show_bug.cgi?id=894370 (currently closed)
patch: https://hg.mozilla.org/projects/nss/rev/56436aa3463f
Discussion:
Statement:
This issue affects the version of nss as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team h
Bugzilla
CVE-2013-1620 nss: TLS CBC padding timing attack [fedora-all]
bugzilla·2013-02-06·CVSS 4.3
CVE-2013-1620 [MEDIUM] CVE-2013-1620 nss: TLS CBC padding timing attack [fedora-all]
CVE-2013-1620 nss: TLS CBC padding timing attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple su
Bugzilla
CVE-2013-1620 nss: TLS CBC padding timing attack
bugzilla·2013-02-06·CVSS 4.3
CVE-2013-1620 [MEDIUM] CVE-2013-1620 nss: TLS CBC padding timing attack
CVE-2013-1620 nss: TLS CBC padding timing attack
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
To perform a successful attack, when TLS is
Bugzilla
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
bugzilla·2013-02-04·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
The paper indicates that with Ope
Bugzilla
Non-constant time CBC decoding results in padding oracle (Lucky Thirteen attack)
bugzilla·2012-12-17
[CRITICAL] Non-constant time CBC decoding results in padding oracle (Lucky Thirteen attack)
Non-constant time CBC decoding results in padding oracle (Lucky Thirteen attack)
Kenny Paterson of Royal Holloway, University of London sent us a
paper that Nadhem AlFardan and he wrote on a new analysis of the
TLS Record Protocol. The paper is NOT yet published.
Lucky Thirteen: Breaking the TLS and DTLS Record Protocols
Nadhem J. AlFardan and Kenneth G. Paterson
Abstract
The Transport Layer Security (TLS) protocol aims to provide
confidentiality and integrity of data in transit across untrusted
networks. TLS has become the de facto secure protocol of choice
for Internet and mobile applications. DTLS is a variant of TLS
that is growing in popularity. In this paper, we present
distinguishing and plaintext recovery attacks against TLS and
DTLS. The attacks are based on a delicate timing a
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlhttp://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2013-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1144.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.isg.rhul.ac.uk/tls/TLStiming.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/57777http://www.securityfocus.com/bid/64758http://www.ubuntu.com/usn/USN-1763-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlhttp://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2013-1135.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1144.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.isg.rhul.ac.uk/tls/TLStiming.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/57777http://www.securityfocus.com/bid/64758http://www.ubuntu.com/usn/USN-1763-1http://www.vmware.com/security/advisories/VMSA-2014-0012.html
2013-02-08
Published