cbcvebase.
CVE-2013-1620
published 2013-02-08

CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation…

medium4.3CVSS 3.1
AVNACMAuNCPINAN
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiannss< nss 2:3.14.3-1 (bookworm)nss 2:3.14.3-1 (bookworm)
mozillanetwork_security_services< 3.14.33.14.3
mozillanss>= 0 < 2:3.14.3-12:3.14.3-1
mozillanss>= 0 < 2:3.14.3-12:3.14.3-1
mozillanss>= 0 < 2:3.14.3-12:3.14.3-1
mozillanss>= 0 < 2:3.14.3-12:3.14.3-1
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oracleglassfish_communications_server
oracleglassfish_server
oracleiplanet_web_proxy_server
oracleiplanet_web_server
oracleiplanet_web_server
oracleopensso
oracletraffic_director
oracletraffic_director
oraclevm_server
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv2.6LOW