CVE-2013-1624
published 2013-02-08CVE-2013-1624: The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a…
PriorityP420medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.97%
85.7th percentile
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
ghsa2.6LOW
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Input Validation in Bouncy Castle
ghsa·2022-05-14·CVSS 2.6
CVE-2013-1624 [LOW] CWE-20 Improper Input Validation in Bouncy Castle
Improper Input Validation in Bouncy Castle
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
OSV
Improper Input Validation in Bouncy Castle
osv·2022-05-14·CVSS 2.6
CVE-2013-1624 [LOW] Improper Input Validation in Bouncy Castle
Improper Input Validation in Bouncy Castle
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
OSV
CVE-2013-1624: The TLS implementation in the Bouncy Castle Java library before 1
osv·2013-02-08·CVSS 2.6
CVE-2013-1624 [LOW] CVE-2013-1624: The TLS implementation in the Bouncy Castle Java library before 1
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Red Hat
bouncycastle: TLS CBC padding timing attack
vendor_redhat·2013-02-04·CVSS 2.6
CVE-2013-1624 [LOW] CWE-385 bouncycastle: TLS CBC padding timing attack
bouncycastle: TLS CBC padding timing attack
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
It was discovered that bouncycastle leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle.
Package: bouncycastle (OpenShif
Debian
CVE-2013-1624: bouncycastle - The TLS implementation in the Bouncy Castle Java library before 1.48 and C# libr...
vendor_debian·2013·CVSS 2.6
CVE-2013-1624 [LOW] CVE-2013-1624: bouncycastle - The TLS implementation in the Bouncy Castle Java library before 1.48 and C# libr...
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Scope: local
bookworm: resolved (fixed in 1.48+dfsg-2)
bullseye: resolved (fixed in 1.48+dfsg-2)
forky: resolved (fixed in 1.48+dfsg-2)
sid: resolved (fixed in 1.48+dfsg-2)
trixie: resolved (fixed in 1.48+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
BPMS 6.0 is affected by CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
bugzilla·2014-01-27·CVSS 4.0
CVE-2013-1624 [MEDIUM] BPMS 6.0 is affected by CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
BPMS 6.0 is affected by CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
https://bugzilla.redhat.com/show_bug.cgi?id=908428
Discussion:
This flaw does not affect EAP. The affected component is bcprov-jdk14-138.jar, which ships as part of the generic deployable zip (but not the EAP deployable zip). Setting this back to 6.0.1?.
---
Seems to be introduced by drools-verifier:
[INFO] +- org.drools:drools-verifier:jar:6.1.0-SNAPSHOT:compile
[INFO] | +- com.google.guava:guava:jar:13.0.1:compile
[INFO] | \- com.lowagie:itext:jar:2.1.2:compile
[INFO] | +- bouncycastle:bcmail-jdk14:jar:138:compile
[INFO] | \- bouncycastle:bcprov-jdk14:jar:138:compile
---
After doing a "mvn dependency:tree" on all of droolsjbpm (non-full build though), we see that bouncycastle comes in only through i
Bugzilla
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [jpp-6.2.0]
bugzilla·2014-01-27·CVSS 4.0
CVE-2013-1624 [MEDIUM] CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [jpp-6.2.0]
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [jpp-6.2.0]
https://bugzilla.redhat.com/show_bug.cgi?id=908428
Discussion:
Recommended fix: Upgrade to bouncycastle >= 1.48
---
Retargeting this to JPP 6.2.0.
---
This was retargeted due to an overwhelming lack of progress. This was exptected to be fixed before 6.2.0.
---
Hi Chess,
can you please provide me a link with reproducer for this issue ?
Thank you,
Filip Kiss
---
Filip, we don't have a reproducer for this flaw. For other product fixes for this CVE, we've been verifying that updated bc jars are in use. The correct bc jars (1.50, need >1.48) are in CR1 as of 2014-09-19.
---
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For
Bugzilla
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [epel-all]
bugzilla·2013-03-12·CVSS 4.0
CVE-2013-1624 [MEDIUM] CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [epel-all]
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [fedora-all]
bugzilla·2013-03-12·CVSS 4.0
CVE-2013-1624 [MEDIUM] CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [fedora-all]
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mu
Bugzilla
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
bugzilla·2013-02-06·CVSS 4.0
CVE-2013-1624 [MEDIUM] CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
CVE-2013-1624 bouncycastle: TLS CBC padding timing attack
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
The paper indicates that with OpenS
Bugzilla
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
bugzilla·2013-02-04·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
A flaw in how TLS/DTLS, when CBC-mode encryption is used, communicates was reported. This vulnerability can allow for a Man-in-the-Middle attacker to recover plaintext from a TLS/DTLS connection, when CBC-mode encryption is used.
This flaw is in the TLS specification, and not a bug in a specific implementation (as such, it affects nearly all implementations). As such, it affects all TLS and DTLS implementations that are compliant with TLS 1.1 or 1.2, or with DTLS 1.0 or 1.2. It also applies to implementations of SSL 3.0 and TLS 1.0 that incorporate countermeasures to deal with previous padding oracle attacks. All TLS/DTLS ciphersuites that include CBC-mode encryption are potentially vulnerable.
The paper indicates that with Ope
http://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.isg.rhul.ac.uk/tls/TLStiming.pdfhttp://openwall.com/lists/oss-security/2013/02/05/24http://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
2013-02-08
Published