Home page logo
/

oss-sec logo oss-sec mailing list archives

Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations
From: Marcus Meissner <meissner () suse de>
Date: Tue, 5 Feb 2013 16:54:54 +0100

On Tue, Feb 05, 2013 at 10:34:23AM +0100, Matthias Weckbecker wrote:
Hi,

has there already been a CVE assigned for the recent "lucky 13" timing
flaw that affects various SSL / TLS implementations (including GnuTLS)?

  http://www.isg.rhul.ac.uk/tls/
  http://www.gnutls.org/security.html#GNUTLS-SA-2013-1

I think this could qualify for CVE for each open source implementation
that's prone.

openssl has released updated packages with a CVE assigned, unclear
whether it covers just openssl or also the others.

http://www.openssl.org/news/secadv_20130205.txt

Ciao, Marcus


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]