4.3
CVSSv2

CVE-2013-1623

Published: 08/02/2013 Updated: 21/02/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The TLS and DTLS implementations in wolfSSL CyaSSL prior to 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote malicious users to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yassl cyassl 2.0.0

yassl cyassl 1.6.0

yassl cyassl 0.3.0

yassl cyassl 0.8.0

yassl cyassl 1.2.0

yassl cyassl 1.0.3

yassl cyassl 0.9.0

yassl cyassl 0.9.6

yassl cyassl 2.3.0

yassl cyassl 2.4.0

yassl cyassl 1.5.6

yassl cyassl 1.8.0

yassl cyassl 0.6.3

yassl cyassl 0.6.2

yassl cyassl 1.0.6

yassl cyassl 1.5.0

yassl cyassl 1.5.4

yassl cyassl 1.0.0

yassl cyassl 1.0.2

yassl cyassl

yassl cyassl 1.9.0

yassl cyassl 0.5.0

yassl cyassl 0.4.0

yassl cyassl 2.0.6

yassl cyassl 1.1.0

yassl cyassl 0.9.8

yassl cyassl 0.9.9

yassl cyassl 2.0.8

yassl cyassl 2.2.0

yassl cyassl 2.0.2

yassl cyassl 1.6.5

yassl cyassl 0.5.5

yassl cyassl 0.6.0

yassl cyassl 0.2.0

yassl cyassl 1.3.0

yassl cyassl 1.4.0

Vendor Advisories

Several security issues were fixed in MySQL ...
Debian Bug report logs - #675872 mysql-server-51: CVE-2012-0882 - one more underspecified security problem Package: mysql-server-51; Maintainer for mysql-server-51 is (unknown); Reported by: Arne Wichmann <aw@fva-wgde> Date: Sun, 3 Jun 2012 19:36:05 UTC Severity: important Found in versions 5163-0+squeeze1, 5161 ...
Debian Bug report logs - #699886 TLS timing attack in yaSSL (Lucky 13) Package: mysql-55; Maintainer for mysql-55 is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Wed, 6 Feb 2013 10:51:01 UTC Severity: serious Tags: patch, pending, securit ...