LWN.net Logo

polarssl: multiple vulnerabilities

Package(s):polarssl CVE #(s):CVE-2013-1621 CVE-2013-1622
Created:February 14, 2013 Updated:February 20, 2013
Description:

From the Debian advisory:

CVE-2013-1621: An array index error might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session

CVE-2013-1622: Malformed CBC data in a TLS session could allow remote attackers to conduct distinguishing attacks via statistical analysis of timing side-channel data for crafted packets.

These appear to be related to the "Lucky Thirteen" vulnerabilities.

Alerts:
Debian DSA-2622-1 2013-02-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds