[Forgot Password]
Login  Register Subscribe

23631

 
 

115084

 
 

97559

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2621-1 openssl -- several

ID: oval:org.secpod.oval:def:600964Date: (C)2013-02-17   (M)2017-09-22
Class: PATCHFamily: unix




Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0166 OpenSSL does not properly perform signature verification for OCSP responses, which allows remote attackers to cause a denial of service via an invalid key. CVE-2013-0169 A timing side channel attack has been found in CBC padding allowing an attacker to recover pieces of plaintext via statistical analysis of crafted packages, known as the "Lucky Thirteen" issue.

Platform:
Debian 6.0
Product:
openssl
Reference:
DSA-2621-1
CVE-2013-0166
CVE-2013-0169
CVE    2
CVE-2013-0169
CVE-2013-0166
CPE    122
cpe:/a:oracle:openjdk:1.7.0
cpe:/a:polarssl:polarssl:0.14.0
cpe:/a:polarssl:polarssl:0.14.2
cpe:/a:polarssl:polarssl:0.14.3
...

© 2013 SecPod Technologies