2013-02-08 20:55:01 2018-10-30 17:26:49

The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Vector

NETWORK

Complexity

HIGH

Authentication

NONE

Confidentiality

PARTIAL

Integrity

PARTIAL

Availability

NONE
Legion of the Bouncy Castle Java Cryptography API 1.43 Legion of the Bouncy Castle Java Cryptography API 1.42 Legion of the Bouncy Castle Java Cryptography API 1.41 Legion of the Bouncy Castle Java Cryptography API 1.40 Legion of the Bouncy Castle Java Cryptography API 1.39 Legion of the Bouncy Castle Java Cryptography API 1.38 Legion of the Bouncy Castle Java Cryptograph API 1.37 Legion of the Bouncy Castle Java Cryptography API 1.36 Legion of the Bouncy Castle Java Cryptography API 1.35 Legion of the Bouncy Castle Java Cryptography API 1.34 Legion of the Bouncy Castle Java Cryptography API 1.33 Legion of the Bouncy Castle Java Cryptography API 1.32 Legion of the Bouncy Castle Java Cryptography API 1.31 Legion of the Bouncy Castle Java Cryptography API 1.30 Legion of the Bouncy Castle Java Cryptography API 1.29 Legion of the Bouncy Castle Java Cryptography API 1.28 Legion of the Bouncy Castle Java Cryptography API 1.27 Legion of the Bouncy Castle Java Cryptography API 1.26 Legion of the Bouncy Castle Java Cryptography API 1.25 Legion of the Bouncy Castle Java Cryptography API 1.24 Legion of the Bouncy Castle Java Cryptography API 1.23 Legion of the Bouncy Castle Java Cryptography API 1.22 Legion of the Bouncy Castle Java Cryptography API 1.21 Legion of the Bouncy Castle Java Cryptography API 1.20 Legion of the Bouncy Castle Java Cryptography API 1.19 Legion of the Bouncy Castle Java Cryptography API 1.18 Legion of the Bouncy Castle Java Cryptography API 1.17 Legion of the Bouncy Castle Java Cryptography API 1.16 Legion of the Bouncy Castle Java Cryptography API 1.15 Legion of the Bouncy Castle Java Cryptography API 1.14 Legion of the Bouncy Castle Java Cryptography API 1.13 Legion of the Bouncy Castle Java Cryptography API 1.12 Legion of the Bouncy Castle Java Cryptography API 1.11 Legion of the Bouncy Castle Java Cryptography API 1.10 Legion of the Bouncy Castle Java Cryptography API 1.09 Legion of the Bouncy Castle Java Cryptography API 1.08 Legion of the Bouncy Castle Java Cryptography API 1.07 Legion of the Bouncy Castle Java Cryptography API 1.06 Legion of the Bouncy Castle Java Cryptography API 1.05 Legion of the Bouncy Castle Java Cryptography API 1.04 Legion of the Bouncy Castle Java Cryptography API 1.03 Legion of the Bouncy Castle Java Cryptography API 1.02 Legion of the Bouncy Castle Java Cryptography API 1.01 Legion of the Bouncy Castle C# Cryptography API 1.7 Legion of the Bouncy Castle C# Cryptography API 1.6.1 Legion of the Bouncy Castle C# Cryptography API 1.5 Legion of the Bouncy Castle C# Cryptography API 1.4 Legion of the Bouncy Castle C# Cryptography API 1.3 Legion of the Bouncy Castle C# Cryptography API 1.2 Legion of the Bouncy Castle C# Cryptography API 1.1 Legion of the Bouncy Castle C# Cryptography API 1.0 Legion of the Bouncy Castle C# Cryptography API 0.0 Legion of the Bouncy Castle Java Cryptography API 1.44 Legion of the Bouncy Castle Java Cryptography API 1.45 Legion of the Bouncy Castle Java Cryptography API 1.46 Legion of the Bouncy Castle Java Cryptography API 1.47