LWN.net Logo

mozilla: distinguishing and plaintext-recovery attacks

Package(s):firefox thunderbird nss CVE #(s):CVE-2013-1620
Created:February 22, 2013 Updated:April 5, 2013
Description: From the CVE entry:

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Alerts:
Mageia MGASA-2013-0063 2013-02-21
Fedora FEDORA-2013-2929 2013-02-28
Fedora FEDORA-2013-2929 2013-02-28
Fedora FEDORA-2013-2929 2013-02-28
Fedora FEDORA-2013-2929 2013-02-28
Fedora FEDORA-2013-3079 2013-03-14
Fedora FEDORA-2013-3079 2013-03-14
Fedora FEDORA-2013-3079 2013-03-14
Fedora FEDORA-2013-3079 2013-03-14
Ubuntu USN-1763-1 2013-03-14
Ubuntu USN-1763-2 2013-03-14
openSUSE openSUSE-SU-2013:0630-1 2013-04-05
Fedora FEDORA-2013-4832 2013-04-05
Fedora FEDORA-2013-4832 2013-04-05
openSUSE openSUSE-SU-2013:0631-1 2013-04-05
Mandriva MDVSA-2013:050 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds