The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28,...
Vulnerability Description
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1619
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/57260
- https://gitorious.org/gnutls/gnutls/commit/328ee22c1b3951e060c7124c7cb1cee592c59bc0
- http://www.gnutls.org/security.html#GNUTLS-SA-2013-1
- http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
- http://secunia.com/advisories/57274
- http://openwall.com/lists/oss-security/2013/02/05/24
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.html
- http://nmav.gnutls.org/2013/02/time-is-money-for-cbc-ciphersuites.html
- http://www.ubuntu.com/usn/USN-1752-1
- http://lists.opensuse.org/opensuse-updates/2013-05/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00009.html
- http://rhn.redhat.com/errata/RHSA-2013-0588.html
- https://gitorious.org/gnutls/gnutls/commit/b8391806cd79095fe566f2401d8c7ad85a64b198
More from gnu
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.