The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Opera_browser | Opera | * | 12.12 (including) |
Opera_browser | Opera | 12.00 (including) | 12.00 (including) |
Opera_browser | Opera | 12.00-beta (including) | 12.00-beta (including) |
Opera_browser | Opera | 12.01 (including) | 12.01 (including) |
Opera_browser | Opera | 12.02 (including) | 12.02 (including) |
Opera_browser | Opera | 12.10 (including) | 12.10 (including) |
Opera_browser | Opera | 12.10-beta (including) | 12.10-beta (including) |
Opera_browser | Opera | 12.11 (including) | 12.11 (including) |