cbcvebase.
CVE-2013-2566
published 2013-03-15

CVE-2013-2566: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct…

medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EXPLOIT
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
fujitsum10-1_firmware>= xcp < xcp2280xcp2280
fujitsum10-4_firmware>= xcp < xcp2280xcp2280
fujitsum10-4s_firmware>= xcp < xcp2280xcp2280
fujitsusparc_enterprise_m3000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m4000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m5000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m8000_firmware>= xcp < xcp_1121xcp_1121
fujitsusparc_enterprise_m9000_firmware>= xcp < xcp_1121xcp_1121
mozillafirefox< 17.0.1117.0.11
mozillafirefox< 25.0.125.0.1
mozillafirefox>= 24.1.0 < 24.1.124.1.1
mozillaseamonkey< 2.22.12.22.1
mozillathunderbird< 24.1.124.1.1
mozillathunderbird_esr< 17.0.1117.0.11
oraclecommunications_application_session_controller3.0.0 – 3.9.1
oraclehttp_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
oracleintegrated_lights_out_manager_firmware3.0.0 – 3.2.11