CVE Vulnerabilities

CVE-2013-1624

Published: Feb 08, 2013 | Modified: May 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Affected Software

NameVendorStart VersionEnd Version
Bc-javaBouncycastle1.01 (including)1.01 (including)
Bc-javaBouncycastle1.02 (including)1.02 (including)
Bc-javaBouncycastle1.03 (including)1.03 (including)
Bc-javaBouncycastle1.04 (including)1.04 (including)
Bc-javaBouncycastle1.05 (including)1.05 (including)
Bc-javaBouncycastle1.06 (including)1.06 (including)
Bc-javaBouncycastle1.07 (including)1.07 (including)
Bc-javaBouncycastle1.08 (including)1.08 (including)
Bc-javaBouncycastle1.09 (including)1.09 (including)
Bc-javaBouncycastle1.10 (including)1.10 (including)
Bc-javaBouncycastle1.11 (including)1.11 (including)
Bc-javaBouncycastle1.12 (including)1.12 (including)
Bc-javaBouncycastle1.13 (including)1.13 (including)
Bc-javaBouncycastle1.14 (including)1.14 (including)
Bc-javaBouncycastle1.15 (including)1.15 (including)
Bc-javaBouncycastle1.16 (including)1.16 (including)
Bc-javaBouncycastle1.17 (including)1.17 (including)
Bc-javaBouncycastle1.18 (including)1.18 (including)
Bc-javaBouncycastle1.19 (including)1.19 (including)
Bc-javaBouncycastle1.20 (including)1.20 (including)
Bc-javaBouncycastle1.21 (including)1.21 (including)
Bc-javaBouncycastle1.22 (including)1.22 (including)
Bc-javaBouncycastle1.23 (including)1.23 (including)
Bc-javaBouncycastle1.24 (including)1.24 (including)
Bc-javaBouncycastle1.25 (including)1.25 (including)
Bc-javaBouncycastle1.26 (including)1.26 (including)
Bc-javaBouncycastle1.27 (including)1.27 (including)
Bc-javaBouncycastle1.28 (including)1.28 (including)
Bc-javaBouncycastle1.29 (including)1.29 (including)
Bc-javaBouncycastle1.30 (including)1.30 (including)
Bc-javaBouncycastle1.31 (including)1.31 (including)
Bc-javaBouncycastle1.32 (including)1.32 (including)
Bc-javaBouncycastle1.33 (including)1.33 (including)
Bc-javaBouncycastle1.34 (including)1.34 (including)
Bc-javaBouncycastle1.35 (including)1.35 (including)
Bc-javaBouncycastle1.36 (including)1.36 (including)
Bc-javaBouncycastle1.37 (including)1.37 (including)
Bc-javaBouncycastle1.38 (including)1.38 (including)
Bc-javaBouncycastle1.39 (including)1.39 (including)
Bc-javaBouncycastle1.40 (including)1.40 (including)
Bc-javaBouncycastle1.41 (including)1.41 (including)
Bc-javaBouncycastle1.42 (including)1.42 (including)
Bc-javaBouncycastle1.43 (including)1.43 (including)
Bc-javaBouncycastle1.44 (including)1.44 (including)
Bc-javaBouncycastle1.45 (including)1.45 (including)
Bc-javaBouncycastle1.46 (including)1.46 (including)
Bc-javaBouncycastle1.47 (including)1.47 (including)
Red Hat JBoss A-MQ 6.1RedHat*
Red Hat JBoss BPMS 6.0RedHat*
Red Hat JBoss BRMS 6.0RedHat*
Red Hat JBoss Fuse 6.1RedHat*
Red Hat JBoss Portal 6.2RedHatbouncycastle*
Red Hat JBoss Web Framework Kit 2.6RedHat*
BouncycastleUbuntuhardy*
BouncycastleUbuntulucid*
BouncycastleUbuntuoneiric*
BouncycastleUbuntuprecise*
BouncycastleUbuntuquantal*
BouncycastleUbunturaring*
BouncycastleUbuntuupstream*

References