Unrated severityNVD Advisory· Published Feb 8, 2013· Updated Apr 29, 2026
CVE-2013-0169
CVE-2013-0169
Description
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
Affected products
70cpe:2.3:a:oracle:openjdk:1.6.0:-:*:*:*:*:*:*+ 46 more
- cpe:2.3:a:oracle:openjdk:1.6.0:-:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update1:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update10:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update11:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update12:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update13:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update14:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update15:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update16:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update17:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update18:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update19:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update2:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update20:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update21:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update22:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update23:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update24:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update25:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update26:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update27:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update29:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update3:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update30:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update31:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update32:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update33:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update34:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update35:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update37:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update38:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update4:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update5:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update6:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.6.0:update7:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:-:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update1:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update10:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update11:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update13:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update2:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update3:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update4:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update5:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update6:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update7:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:1.7.0:update9:*:*:*:*:*:*
cpe:2.3:a:polarssl:polarssl:0.10.0:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:polarssl:polarssl:0.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.13.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.14.2:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.14.3:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.99:pre1:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.99:pre3:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.99:pre4:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:0.99:pre5:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.0:rc0:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
55- blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/nvdThird Party Advisory
- lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlnvdThird Party Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0587.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0782.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0783.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0833.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1455.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1456.htmlnvdThird Party Advisory
- secunia.com/advisories/53623nvdThird Party Advisory
- secunia.com/advisories/55108nvdThird Party Advisory
- secunia.com/advisories/55139nvdThird Party Advisory
- secunia.com/advisories/55322nvdThird Party Advisory
- secunia.com/advisories/55350nvdThird Party Advisory
- secunia.com/advisories/55351nvdThird Party Advisory
- security.gentoo.org/glsa/glsa-201406-32.xmlnvdThird Party Advisory
- support.apple.com/kb/HT5880nvdThird Party Advisory
- www-01.ibm.com/support/docview.wssnvdThird Party Advisory
- www.debian.org/security/2013/dsa-2621nvdThird Party Advisory
- www.debian.org/security/2013/dsa-2622nvdThird Party Advisory
- www.isg.rhul.ac.uk/tls/TLStiming.pdfnvdThird Party Advisory
- www.kb.cert.org/vuls/id/737740nvdThird Party AdvisoryUS Government Resource
- www.mandriva.com/security/advisoriesnvdThird Party Advisory
- www.matrixssl.org/news.htmlnvdThird Party Advisory
- www.openssl.org/news/secadv_20130204.txtnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/57778nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1029190nvdThird Party AdvisoryVDB Entry
- www.splunk.com/view/SP-CAAAHXGnvdThird Party Advisory
- www.ubuntu.com/usn/USN-1735-1nvdThird Party Advisory
- www.us-cert.gov/cas/techalerts/TA13-051A.htmlnvdThird Party AdvisoryUS Government Resource
- cert-portal.siemens.com/productcert/pdf/ssa-556833.pdfnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00029.htmlnvdThird Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608nvdThird Party Advisory
- polarssl.org/tech-updates/releases/polarssl-1.2.5-releasednvdVendor Advisory
- puppet.com/security/cve/cve-2013-0169nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party Advisory
- wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084nvdThird Party Advisory
- openwall.com/lists/oss-security/2013/02/05/24nvdMailing List
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841nvdTool Signature
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016nvdTool Signature
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424nvdTool Signature
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540nvdTool Signature
News mentions
0No linked articles in our index yet.