LWN.net Logo

“Lucky Thirteen” attack snarfs cookies protected by SSL encryption (ars technica)

“Lucky Thirteen” attack snarfs cookies protected by SSL encryption (ars technica)

Posted Feb 6, 2013 7:58 UTC (Wed) by ametlwn (subscriber, #10544)
Parent article: “Lucky Thirteen” attack snarfs cookies protected by SSL encryption (ars technica)

This was fixed in GnuTLS on Moday: <http://lists.gnupg.org/pipermail/gnutls-devel/2013-Februa...>
GnuTLS security ID: GNUTLS-SA-2013-1
Lucky 13 is CVE-2013-0169, CVE-2013-1619 is the identifier for the issue specific to the GnuTLS implementation. <http://openwall.com/lists/oss-security/2013/02/05/24>.
Nikos Mavrogiannopoulos has made a nice writeup here: <http://nikmav.blogspot.be/2013/02/time-is-money-for-cbc-c...>.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds