Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-1618 at MITRE


The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
CVSS v2 Scores
  National Vulnerability Database
Base Score 4.04
Vector AV:N/AC:H/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

SUSE information

SUSE Bugzilla entries: 801233 [RESOLVED / FIXED], 802184 [RESOLVED / FIXED]

SUSE Security Advisories: