[Forgot Password]
Login  Register Subscribe

24003

 
 

131425

 
 

103942

 
 

909

 
 

84057

 
 

133

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2621-1 openssl -- several

ID: oval:org.secpod.oval:def:600964Date: (C)2013-02-17   (M)2017-12-13
Class: PATCHFamily: unix




Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0166 OpenSSL does not properly perform signature verification for OCSP responses, which allows remote attackers to cause a denial of service via an invalid key. CVE-2013-0169 A timing side channel attack has been found in CBC padding allowing an attacker to recover pieces of plaintext via statistical analysis of crafted packages, known as the "Lucky Thirteen" issue.

Platform:
Debian 6.0
Product:
openssl
Reference:
DSA-2621-1
CVE-2013-0166
CVE-2013-0169
CVE    2
CVE-2013-0169
CVE-2013-0166
CPE    94
cpe:/a:openssl:openssl:0.9.7j
cpe:/a:openssl:openssl:0.9.7k
cpe:/a:openssl:openssl:0.9.7l
cpe:/a:openssl:openssl:0.9.7m
...

© 2013 SecPod Technologies