oss-sec mailing list archives
Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations
From: Shawn <citypw () gmail com>
Date: Tue, 5 Feb 2013 23:36:34 +0800
hi Matthias, On Tue, Feb 5, 2013 at 5:34 PM, Matthias Weckbecker <mweckbecker () suse de> wrote:
Hi, has there already been a CVE assigned for the recent "lucky 13" timing flaw that affects various SSL / TLS implementations (including GnuTLS)? http://www.isg.rhul.ac.uk/tls/ http://www.gnutls.org/security.html#GNUTLS-SA-2013-1 I think this could qualify for CVE for each open source implementation that's prone.
According to "OpenSSL Security Advisory [05 Feb 2013]": http://www.openssl.org/news/secadv_20130204.txt It seems already had a CVE-id. But I couldn't find by googled... -- GNU powered it... GPL protect it... God blessing it... regards Shawn
Current thread:
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations, (continued)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Matthias Weckbecker (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Marcus Meissner (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Vincent Danen (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations cve-assign (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Vincent Danen (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations cve-assign (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations cve-assign (Feb 05)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Hanno Böck (Feb 07)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Kurt Seifried (Feb 07)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations cve-assign (Feb 07)
- Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations Vincent Danen (Feb 05)