Upstream information

CVE-2013-1618 at MITRE

Description

The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4
Vector AV:N/AC:H/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 801233 [RESOLVED / FIXED], 802184 [RESOLVED / FIXED]

SUSE Security Advisories:

    openSUSE-SU-2013:0289-1 openSUSE-SU-2013:0289-2


SUSE Timeline for this CVE

CVE page created: Fri Jun 28 13:28:49 2013
CVE page last modified: Thu Dec 7 13:06:00 2023