[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2621-1 openssl -- several

ID: oval:org.secpod.oval:def:600964Date: (C)2013-02-17   (M)2017-12-13
Class: PATCHFamily: unix




Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0166 OpenSSL does not properly perform signature verification for OCSP responses, which allows remote attackers to cause a denial of service via an invalid key. CVE-2013-0169 A timing side channel attack has been found in CBC padding allowing an attacker to recover pieces of plaintext via statistical analysis of crafted packages, known as the "Lucky Thirteen" issue.

Platform:
Debian 6.0
Product:
openssl
Reference:
DSA-2621-1
CVE-2013-0166
CVE-2013-0169
CVE    2
CVE-2013-0166
CVE-2013-0169
CPE    94
cpe:/o:debian:debian_linux:6.0
cpe:/a:openssl:openssl:1.0.0h
cpe:/a:openssl:openssl:1.0.0j
cpe:/a:openssl:openssl:1.0.0i
...

© 2013 SecPod Technologies