TLS Vulnerability in Mozilla Network Security Services
CVE-2013-1620
Currently unrated
What is CVE-2013-1620?
A vulnerability in the TLS implementation of Mozilla's Network Security Services (NSS) has been identified, which fails to adequately protect against timing side-channel attacks during the processing of malformed CBC padding. This flaw allows attackers to conduct distinguishing attacks and recover plaintext through statistical analysis of timing data from specially crafted packets. The weakness is closely related to other documented vulnerabilities and may present significant security risks to affected systems.