4.3
CVSSv2

CVE-2013-1621

Published: 08/02/2013 Updated: 08/03/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Array index error in the SSL module in PolarSSL prior to 1.2.5 might allow remote malicious users to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session, a different vulnerability than CVE-2013-0169.

Vulnerable Product Search on Vulmon Subscribe to Product

polarssl polarssl 1.2.0

polarssl polarssl 1.1.5

polarssl polarssl 0.14.3

polarssl polarssl 0.99

polarssl polarssl 1.1.0

polarssl polarssl 1.1.1

polarssl polarssl

polarssl polarssl 1.2.3

polarssl polarssl 0.14.0

polarssl polarssl 0.14.2

polarssl polarssl 0.12.1

polarssl polarssl 0.11.1

polarssl polarssl 0.11.0

polarssl polarssl 1.0.0

polarssl polarssl 1.1.4

polarssl polarssl 1.1.3

polarssl polarssl 0.12.0

polarssl polarssl 1.1.2

polarssl polarssl 1.2.2

polarssl polarssl 1.2.1

polarssl polarssl 0.13.1

polarssl polarssl 0.10.0

polarssl polarssl 0.10.1

Vendor Advisories

Debian Bug report logs - #699887 TLS timing attack in polarssl (Lucky 13) Package: polarssl; Maintainer for polarssl is Roland Stigge <stigge@antcomde>; Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Wed, 6 Feb 2013 10:51:04 UTC Severity: serious Tags: security Fixed in versions polarssl/125-1, polarssl/1 ...
Multiple vulnerabilities have been found in PolarSSL The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0169 A timing side channel attack has been found in CBC padding allowing an attacker to recover pieces of plaintext via statistical analysis of crafted packages, known as the Lucky Thirteen is ...