4

CVE-2013-1618

The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opera ≫ Opera Browser Version <= 12.12
Opera ≫ Opera Browser Version 12.00
Opera ≫ Opera Browser Version 12.00 Update beta
Opera ≫ Opera Browser Version 12.01
Opera ≫ Opera Browser Version 12.02
Opera ≫ Opera Browser Version 12.10
Opera ≫ Opera Browser Version 12.10 Update beta
Opera ≫ Opera Browser Version 12.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.16% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-updates/2013-02/msg00038.html
http://www.opera.com/docs/changelogs/unified/1213/
http://openwall.com/lists/oss-security/2013/02/05/24
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
http://www.opera.com/support/kb/view/1044/
Vendor Advisory