|
|
| |
|
| |
polarssl: multiple vulnerabilities
| Package(s): | polarssl |
CVE #(s): | CVE-2013-1621
CVE-2013-1622
|
| Created: | February 14, 2013 |
Updated: | February 20, 2013 |
| Description: |
From the Debian advisory:
CVE-2013-1621:
An array index error might allow remote attackers to cause a denial
of service via vectors involving a crafted padding-length value
during validation of CBC padding in a TLS session
CVE-2013-1622:
Malformed CBC data in a TLS session could allow remote attackers to
conduct distinguishing attacks via statistical analysis of timing
side-channel data for crafted packets.
These appear to be related to the "Lucky Thirteen" vulnerabilities. |
| Alerts: |
|
( Log in to post comments)
|
|
|