{
    "CVE_data_meta": {
        "ASSIGNER": "secalert@redhat.com",
        "ID": "CVE-2013-0169",
        "STATE": "PUBLIC"
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "product": {
                        "product_data": [
                            {
                                "product_name": "n/a",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_value": "n/a"
                                        }
                                    ]
                                }
                            }
                        ]
                    },
                    "vendor_name": "n/a"
                }
            ]
        }
    },
    "data_format": "MITRE",
    "data_type": "CVE",
    "data_version": "4.0",
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the \"Lucky Thirteen\" issue."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "n/a"
                    }
                ]
            }
        ]
    },
    "references": {
        "reference_data": [
            {
                "name": "[debian-lts-announce] 20180925 [SECURITY] [DLA 1518-1] polarssl security update",
                "refsource": "MLIST",
                "url": "https://lists.debian.org/debian-lts-announce/2018/09/msg00029.html"
            },
            {
                "name": "http://www.matrixssl.org/news.html",
                "refsource": "CONFIRM",
                "url": "http://www.matrixssl.org/news.html"
            },
            {
                "name": "RHSA-2013:0587",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-0587.html"
            },
            {
                "name": "GLSA-201406-32",
                "refsource": "GENTOO",
                "url": "http://security.gentoo.org/glsa/glsa-201406-32.xml"
            },
            {
                "name": "FEDORA-2013-4403",
                "refsource": "FEDORA",
                "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html"
            },
            {
                "name": "TA13-051A",
                "refsource": "CERT",
                "url": "http://www.us-cert.gov/cas/techalerts/TA13-051A.html"
            },
            {
                "name": "oval:org.mitre.oval:def:19016",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016"
            },
            {
                "name": "MDVSA-2013:095",
                "refsource": "MANDRIVA",
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:095"
            },
            {
                "name": "55139",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/55139"
            },
            {
                "name": "55322",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/55322"
            },
            {
                "name": "oval:org.mitre.oval:def:19608",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608"
            },
            {
                "name": "http://www.openssl.org/news/secadv_20130204.txt",
                "refsource": "CONFIRM",
                "url": "http://www.openssl.org/news/secadv_20130204.txt"
            },
            {
                "name": "http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/",
                "refsource": "MISC",
                "url": "http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/"
            },
            {
                "name": "https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084",
                "refsource": "CONFIRM",
                "url": "https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084"
            },
            {
                "name": "http://www.isg.rhul.ac.uk/tls/TLStiming.pdf",
                "refsource": "MISC",
                "url": "http://www.isg.rhul.ac.uk/tls/TLStiming.pdf"
            },
            {
                "name": "http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html",
                "refsource": "CONFIRM",
                "url": "http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html"
            },
            {
                "name": "openSUSE-SU-2013:0378",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html"
            },
            {
                "name": "DSA-2622",
                "refsource": "DEBIAN",
                "url": "http://www.debian.org/security/2013/dsa-2622"
            },
            {
                "name": "57778",
                "refsource": "BID",
                "url": "http://www.securityfocus.com/bid/57778"
            },
            {
                "name": "http://www-01.ibm.com/support/docview.wss?uid=swg21644047",
                "refsource": "CONFIRM",
                "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21644047"
            },
            {
                "name": "[oss-security] 20130205 Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations",
                "refsource": "MLIST",
                "url": "http://openwall.com/lists/oss-security/2013/02/05/24"
            },
            {
                "name": "RHSA-2013:1455",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-1455.html"
            },
            {
                "name": "55351",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/55351"
            },
            {
                "name": "HPSBUX02856",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136396549913849&w=2"
            },
            {
                "name": "https://puppet.com/security/cve/cve-2013-0169",
                "refsource": "CONFIRM",
                "url": "https://puppet.com/security/cve/cve-2013-0169"
            },
            {
                "name": "SSRT101289",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=137545771702053&w=2"
            },
            {
                "name": "openSUSE-SU-2016:0640",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html"
            },
            {
                "name": "SSRT101108",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136432043316835&w=2"
            },
            {
                "name": "SUSE-SU-2013:0328",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html"
            },
            {
                "name": "RHSA-2013:0833",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-0833.html"
            },
            {
                "name": "USN-1735-1",
                "refsource": "UBUNTU",
                "url": "http://www.ubuntu.com/usn/USN-1735-1"
            },
            {
                "name": "SUSE-SU-2014:0320",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html"
            },
            {
                "name": "HPSBUX02857",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136439120408139&w=2"
            },
            {
                "name": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001",
                "refsource": "CONFIRM",
                "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001"
            },
            {
                "name": "53623",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/53623"
            },
            {
                "name": "SUSE-SU-2013:0701",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html"
            },
            {
                "name": "VU#737740",
                "refsource": "CERT-VN",
                "url": "http://www.kb.cert.org/vuls/id/737740"
            },
            {
                "name": "oval:org.mitre.oval:def:19424",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424"
            },
            {
                "name": "HPSBUX02909",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=137545771702053&w=2"
            },
            {
                "name": "DSA-2621",
                "refsource": "DEBIAN",
                "url": "http://www.debian.org/security/2013/dsa-2621"
            },
            {
                "name": "RHSA-2013:0783",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-0783.html"
            },
            {
                "name": "HPSBMU02874",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136733161405818&w=2"
            },
            {
                "name": "APPLE-SA-2013-09-12-1",
                "refsource": "APPLE",
                "url": "http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html"
            },
            {
                "name": "55108",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/55108"
            },
            {
                "name": "RHSA-2013:0782",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-0782.html"
            },
            {
                "name": "HPSBOV02852",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136432043316835&w=2"
            },
            {
                "name": "SSRT101103",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136439120408139&w=2"
            },
            {
                "name": "SSRT101104",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136396549913849&w=2"
            },
            {
                "name": "SUSE-SU-2015:0578",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html"
            },
            {
                "name": "openSUSE-SU-2013:0375",
                "refsource": "SUSE",
                "url": "http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html"
            },
            {
                "name": "https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released",
                "refsource": "CONFIRM",
                "url": "https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released"
            },
            {
                "name": "oval:org.mitre.oval:def:19540",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540"
            },
            {
                "name": "1029190",
                "refsource": "SECTRACK",
                "url": "http://www.securitytracker.com/id/1029190"
            },
            {
                "name": "oval:org.mitre.oval:def:18841",
                "refsource": "OVAL",
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841"
            },
            {
                "name": "http://www.splunk.com/view/SP-CAAAHXG",
                "refsource": "CONFIRM",
                "url": "http://www.splunk.com/view/SP-CAAAHXG"
            },
            {
                "name": "RHSA-2013:1456",
                "refsource": "REDHAT",
                "url": "http://rhn.redhat.com/errata/RHSA-2013-1456.html"
            },
            {
                "name": "http://support.apple.com/kb/HT5880",
                "refsource": "CONFIRM",
                "url": "http://support.apple.com/kb/HT5880"
            },
            {
                "name": "SSRT101184",
                "refsource": "HP",
                "url": "http://marc.info/?l=bugtraq&m=136733161405818&w=2"
            },
            {
                "name": "55350",
                "refsource": "SECUNIA",
                "url": "http://secunia.com/advisories/55350"
            },
            {
                "refsource": "CONFIRM",
                "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf",
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf"
            }
        ]
    }
}