Cryptographic Issues Affecting openssl package, versions >=1.0.0
Snyk CVSS
Attack Complexity
High
Threat Intelligence
EPSS
0.54% (75th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-COCOAPODS-OPENSSL-471325
- published 2 Oct 2019
- disclosed 6 Dec 2012
- credit Unknown
Introduced: 6 Dec 2012
CVE-2013-0169 Open this link in a new tabHow to fix?
There is no fixed version for OpenSSL
.
Overview
OpenSSL is a SSL/TLS and Crypto toolkit. Deprecated in Mac OS and gone in iOS, this spec gives your project non-deprecated OpenSSL support.
Affected versions of this package are vulnerable to Cryptographic Issues. OpenSSL is vulnerable to timing attacks. The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2 doesn't check MAC addresses in constant time during the processing of a malformed CBC padding. This is also known as the "Lucky Thirteen" issue.
References
- Apple Security Advisory
- Apple Security Announcement
- CERT
- Cert Vulnerability Note
- CONFIRM
- CONFIRM
- CONFIRM
- CONFIRM
- CONFIRM
- CONFIRM
- CONFIRM
- CONFIRM
- Debian Security Advisory
- Debian Security Advisory
- Debian Security Announcement
- Fedora Security Announcement
- Gentoo Security Advisory
- GitHub Commit
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- IBM Security Bulletin
- MISC
- MISC
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- Oracle Security Bulletin
- OSS security Advisory
- Oval Security
- Oval Security
- Oval Security
- Oval Security
- Oval Security
- RedHat Security Advisory
- RedHat Security Advisory
- RedHat Security Advisory
- RedHat Security Advisory
- RedHat Security Advisory
- RedHat Security Advisory
- Secunia Advisory
- Secunia Advisory
- Secunia Advisory
- Secunia Advisory
- Secunia Advisory
- Secunia Advisory
- Security Focus
- Security Tracker
- Ubuntu Security Advisory