TLS Vulnerability in Mozilla Network Security Services
CVE-2013-1620

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
8 February 2013

What is CVE-2013-1620?

A vulnerability in the TLS implementation of Mozilla's Network Security Services (NSS) has been identified, which fails to adequately protect against timing side-channel attacks during the processing of malformed CBC padding. This flaw allows attackers to conduct distinguishing attacks and recover plaintext through statistical analysis of timing data from specially crafted packets. The weakness is closely related to other documented vulnerabilities and may present significant security risks to affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.