[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

114563

 
 

909

 
 

88860

 
 

136

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2621-1 openssl -- several

ID: oval:org.secpod.oval:def:600964Date: (C)2013-02-17   (M)2018-10-04
Class: PATCHFamily: unix




Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0166 OpenSSL does not properly perform signature verification for OCSP responses, which allows remote attackers to cause a denial of service via an invalid key. CVE-2013-0169 A timing side channel attack has been found in CBC padding allowing an attacker to recover pieces of plaintext via statistical analysis of crafted packages, known as the "Lucky Thirteen" issue.

Platform:
Debian 6.0
Product:
openssl
Reference:
DSA-2621-1
CVE-2013-0166
CVE-2013-0169
CVE    2
CVE-2013-0166
CVE-2013-0169
CPE    94
cpe:/a:openssl:openssl:1.0.0h
cpe:/a:openssl:openssl:0.9.7m
cpe:/a:openssl:openssl:0.9.8m:beta1
cpe:/a:openssl:openssl:1.0.1
...

© SecPod Technologies