2.6
LOW
CVE-2013-0169
OpenSSL and OpenJDK TLS/DTLS Padding Oracle Attacks
Description

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

INFO

Published Date :

Feb. 8, 2013, 7:55 p.m.

Last Modified :

May 12, 2023, 12:58 p.m.

Remotely Exploitable :

Yes !

Impact Score :

2.9

Exploitability Score :

4.9
Public PoC/Exploit Available at Github

CVE-2013-0169 has a 30 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2013-0169 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Openssl openssl
1 Oracle openjdk
1 Polarssl polarssl
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2013-0169.

URL Resource
http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/ Third Party Advisory
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html Mailing List Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html Third Party Advisory
http://marc.info/?l=bugtraq&m=136396549913849&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136432043316835&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136439120408139&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136733161405818&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=137545771702053&w=2 Third Party Advisory
http://openwall.com/lists/oss-security/2013/02/05/24 Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0587.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0782.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0783.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0833.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1456.html Third Party Advisory
http://secunia.com/advisories/53623 Third Party Advisory
http://secunia.com/advisories/55108 Third Party Advisory
http://secunia.com/advisories/55139 Third Party Advisory
http://secunia.com/advisories/55322 Third Party Advisory
http://secunia.com/advisories/55350 Third Party Advisory
http://secunia.com/advisories/55351 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://support.apple.com/kb/HT5880 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21644047 Third Party Advisory
http://www.debian.org/security/2013/dsa-2621 Third Party Advisory
http://www.debian.org/security/2013/dsa-2622 Third Party Advisory
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf Third Party Advisory
http://www.kb.cert.org/vuls/id/737740 Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 Third Party Advisory
http://www.matrixssl.org/news.html Third Party Advisory
http://www.openssl.org/news/secadv_20130204.txt Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html Third Party Advisory
http://www.securityfocus.com/bid/57778 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029190 Third Party Advisory VDB Entry
http://www.splunk.com/view/SP-CAAAHXG Third Party Advisory
http://www.ubuntu.com/usn/USN-1735-1 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA13-051A.html Third Party Advisory US Government Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/09/msg00029.html Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841 Tool Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016 Tool Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424 Tool Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540 Tool Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608 Third Party Advisory
https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released Vendor Advisory
https://puppet.com/security/cve/cve-2013-0169 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001 Third Party Advisory
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084 Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Security scripts

Dockerfile Makefile Python Shell

Updated: 5 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : March 24, 2024, 2:48 p.m. This repo has been linked 1 different CVEs too.

None

Dockerfile Makefile Python Shell HTML

Updated: 7 months, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : Feb. 2, 2024, 6:10 p.m. This repo has been linked 1 different CVEs too.

None

Dockerfile Makefile Python Shell

Updated: 11 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Sept. 25, 2023, 4:04 p.m. This repo has been linked 1 different CVEs too.

Домашнее задание к занятию «Элементы безопасности информационных систем»

Updated: 1 year, 3 months ago
0 stars 0 fork 0 watcher
Born at : April 5, 2023, 10:39 a.m. This repo has been linked 17 different CVEs too.

tlslite-ng

Makefile Python Shell HTML

Updated: 1 year, 6 months ago
0 stars 0 fork 0 watcher
Born at : March 13, 2023, 12:08 p.m. This repo has been linked 4 different CVEs too.

None

Updated: 1 year, 6 months ago
0 stars 0 fork 0 watcher
Born at : March 13, 2023, 9:44 a.m. This repo has been linked 17 different CVEs too.

None

Updated: 1 week, 4 days ago
5 stars 0 fork 0 watcher
Born at : Feb. 23, 2023, 5:42 a.m. This repo has been linked 455 different CVEs too.

None

Updated: 1 year, 7 months ago
0 stars 0 fork 0 watcher
Born at : Feb. 11, 2023, 7:59 a.m. This repo has been linked 17 different CVEs too.

None

HCL Dockerfile Shell Ruby Go Jinja Python PowerShell HTML CSS

Updated: 1 year, 7 months ago
1 stars 0 fork 0 watcher
Born at : Jan. 17, 2023, 3:17 p.m. This repo has been linked 17 different CVEs too.

None

Updated: 1 year, 8 months ago
0 stars 0 fork 0 watcher
Born at : Jan. 11, 2023, 1:21 p.m. This repo has been linked 1042 different CVEs too.

None

Makefile Python Shell HTML

Updated: 1 year, 11 months ago
0 stars 0 fork 0 watcher
Born at : Sept. 27, 2022, 7:54 p.m. This repo has been linked 4 different CVEs too.

[EN] Hardware hacking: D-Link DIR-655 WiFI router

Classic ASP

Updated: 2 years, 2 months ago
0 stars 0 fork 0 watcher
Born at : July 2, 2022, 5:57 p.m. This repo has been linked 14 different CVEs too.

Fast IP Lookups for Open Ports and Vulnerabilities

r rstats shodan shodan-api

R

Updated: 3 months, 3 weeks ago
3 stars 1 fork 1 watcher
Born at : June 20, 2022, 1:53 p.m. This repo has been linked 50 different CVEs too.

None

Updated: 2 years, 3 months ago
0 stars 0 fork 0 watcher
Born at : June 1, 2022, 3:06 p.m. This repo has been linked 16 different CVEs too.

None

Updated: 2 years, 6 months ago
0 stars 0 fork 0 watcher
Born at : Feb. 26, 2022, 11:12 a.m. This repo has been linked 17 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2013-0169 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2013-0169 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Modified Analysis by [email protected]

    May. 12, 2023

    Action Type Old Value New Value
    Changed CPE Configuration OR *cpe:2.3:a:oracle:openjdk:-:*:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.8.0:*:*:*:*:*:*:* OR *cpe:2.3:a:oracle:openjdk:1.6.0:-:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update1:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update10:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update11:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update12:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update13:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update14:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update15:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update16:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update17:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update18:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update19:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update2:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update20:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update21:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update22:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update23:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update24:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update25:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update26:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update27:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update29:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update3:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update30:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update31:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update32:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update33:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update34:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update35:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update37:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update38:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update4:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update5:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update6:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.6.0:update7:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:-:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update1:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update10:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update11:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update13:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update2:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update3:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update4:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update5:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update6:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update7:*:*:*:*:*:* *cpe:2.3:a:oracle:openjdk:1.7.0:update9:*:*:*:*:*:*
  • Modified Analysis by [email protected]

    Sep. 23, 2019

    Action Type Old Value New Value
    Changed Evaluator Description Per http://www.openssl.org/news/vulnerabilities.html: Fixed in OpenSSL 1.0.1d (Affected 1.0.1c, 1.0.1b, 1.0.1a, 1.0.1) Fixed in OpenSSL 1.0.0k (Affected 1.0.0j, 1.0.0i, 1.0.0g, 1.0.0f, 1.0.0e, 1.0.0d, 1.0.0c, 1.0.0b, 1.0.0a, 1.0.0) Fixed in OpenSSL 0.9.8y (Affected 0.9.8x, 0.9.8w, 0.9.8v, 0.9.8u, 0.9.8t, 0.9.8s, 0.9.8r, 0.9.8q, 0.9.8p, 0.9.8o, 0.9.8n, 0.9.8m, 0.9.8l, 0.9.8k, 0.9.8j, 0.9.8i, 0.9.8h, 0.9.8g, 0.9.8f, 0.9.8d, 0.9.8c, 0.9.8b, 0.9.8a, 0.9.8) Per http://www.openssl.org/news/vulnerabilities.html: Fixed in OpenSSL 1.0.1d (Affected 1.0.1c, 1.0.1b, 1.0.1a, 1.0.1) Fixed in OpenSSL 1.0.0k (Affected 1.0.0j, 1.0.0i, 1.0.0g, 1.0.0f, 1.0.0e, 1.0.0d, 1.0.0c, 1.0.0b, 1.0.0a, 1.0.0) Fixed in OpenSSL 0.9.8y (Affected 0.9.8x, 0.9.8w, 0.9.8v, 0.9.8u, 0.9.8t, 0.9.8s, 0.9.8r, 0.9.8q, 0.9.8p, 0.9.8o, 0.9.8n, 0.9.8m, 0.9.8l, 0.9.8k, 0.9.8j, 0.9.8i, 0.9.8h, 0.9.8g, 0.9.8f, 0.9.8d, 0.9.8c, 0.9.8b, 0.9.8a, 0.9.8) Affected users should upgrade to OpenSSL 1.0.1e, 1.0.0k or 0.9.8y (The fix in 1.0.1d wasn't complete, so please use 1.0.1e or later)
    Changed Reference Type http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/ No Types Assigned http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/ Third Party Advisory
    Changed Reference Type http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html No Types Assigned http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html Mailing List, Third Party Advisory
    Changed Reference Type http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html No Types Assigned http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html Third Party Advisory
    Changed Reference Type http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html No Types Assigned http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=136396549913849&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=136396549913849&w=2 Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=136432043316835&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=136432043316835&w=2 Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=136439120408139&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=136439120408139&w=2 Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=136733161405818&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=136733161405818&w=2 Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=137545771702053&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=137545771702053&w=2 Third Party Advisory
    Changed Reference Type http://openwall.com/lists/oss-security/2013/02/05/24 No Types Assigned http://openwall.com/lists/oss-security/2013/02/05/24 Mailing List
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-0587.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-0587.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-0782.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-0782.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-0783.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-0783.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-0833.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-0833.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-1455.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2013-1456.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2013-1456.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/53623 No Types Assigned http://secunia.com/advisories/53623 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/55108 No Types Assigned http://secunia.com/advisories/55108 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/55139 No Types Assigned http://secunia.com/advisories/55139 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/55322 No Types Assigned http://secunia.com/advisories/55322 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/55350 No Types Assigned http://secunia.com/advisories/55350 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/55351 No Types Assigned http://secunia.com/advisories/55351 Third Party Advisory
    Changed Reference Type http://security.gentoo.org/glsa/glsa-201406-32.xml No Types Assigned http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
    Changed Reference Type http://support.apple.com/kb/HT5880 No Types Assigned http://support.apple.com/kb/HT5880 Third Party Advisory
    Changed Reference Type http://www.debian.org/security/2013/dsa-2621 No Types Assigned http://www.debian.org/security/2013/dsa-2621 Third Party Advisory
    Changed Reference Type http://www.debian.org/security/2013/dsa-2622 No Types Assigned http://www.debian.org/security/2013/dsa-2622 Third Party Advisory
    Changed Reference Type http://www.isg.rhul.ac.uk/tls/TLStiming.pdf No Types Assigned http://www.isg.rhul.ac.uk/tls/TLStiming.pdf Third Party Advisory
    Changed Reference Type http://www.kb.cert.org/vuls/id/737740 US Government Resource http://www.kb.cert.org/vuls/id/737740 Third Party Advisory, US Government Resource
    Changed Reference Type http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 No Types Assigned http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 Third Party Advisory
    Changed Reference Type http://www.matrixssl.org/news.html No Types Assigned http://www.matrixssl.org/news.html Third Party Advisory
    Changed Reference Type http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html No Types Assigned http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/bid/57778 No Types Assigned http://www.securityfocus.com/bid/57778 Third Party Advisory, VDB Entry
    Changed Reference Type http://www.securitytracker.com/id/1029190 No Types Assigned http://www.securitytracker.com/id/1029190 Third Party Advisory, VDB Entry
    Changed Reference Type http://www.splunk.com/view/SP-CAAAHXG No Types Assigned http://www.splunk.com/view/SP-CAAAHXG Third Party Advisory
    Changed Reference Type http://www.ubuntu.com/usn/USN-1735-1 No Types Assigned http://www.ubuntu.com/usn/USN-1735-1 Third Party Advisory
    Changed Reference Type http://www.us-cert.gov/cas/techalerts/TA13-051A.html US Government Resource http://www.us-cert.gov/cas/techalerts/TA13-051A.html Third Party Advisory, US Government Resource
    Changed Reference Type http://www-01.ibm.com/support/docview.wss?uid=swg21644047 No Types Assigned http://www-01.ibm.com/support/docview.wss?uid=swg21644047 Third Party Advisory
    Changed Reference Type https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf No Types Assigned https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf Third Party Advisory
    Changed Reference Type https://lists.debian.org/debian-lts-announce/2018/09/msg00029.html No Types Assigned https://lists.debian.org/debian-lts-announce/2018/09/msg00029.html Third Party Advisory
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841 Tool Signature
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016 Tool Signature
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424 Tool Signature
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540 Tool Signature
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608 Third Party Advisory
    Changed Reference Type https://puppet.com/security/cve/cve-2013-0169 No Types Assigned https://puppet.com/security/cve/cve-2013-0169 Third Party Advisory
    Changed Reference Type https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001 No Types Assigned https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001 Third Party Advisory
    Changed Reference Type https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084 No Types Assigned https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0084 Third Party Advisory
    Changed CPE Configuration OR *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8l:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8m:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8n:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8o:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8p:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8q:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8r:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8s:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8t:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8u:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8v:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8w:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8x:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:* OR *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 0.9.8 up to (including) 0.9.8x *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (including) 1.0.0j *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.1 up to (including) 1.0.1d
  • CVE Modified by [email protected]

    Jul. 09, 2019

    Action Type Old Value New Value
    Added Reference https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf [No Types Assigned]
  • CVE Modified by [email protected]

    Sep. 26, 2018

    Action Type Old Value New Value
    Added Reference https://lists.debian.org/debian-lts-announce/2018/09/msg00029.html [No Types Assigned]
  • CVE Modified by [email protected]

    Aug. 09, 2018

    Action Type Old Value New Value
    Added Reference https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001 [No Types Assigned]
  • CVE Modified by [email protected]

    Dec. 09, 2017

    Action Type Old Value New Value
    Added Reference https://puppet.com/security/cve/cve-2013-0169 [No Types Assigned]
  • CVE Modified by [email protected]

    Sep. 19, 2017

    Action Type Old Value New Value
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19540 [No Types Assigned]
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19424 [No Types Assigned]
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18841 [No Types Assigned]
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19016 [No Types Assigned]
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19608 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19608 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19540 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19424 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19016 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18841 [No Types Assigned]
  • CVE Modified by [email protected]

    Dec. 03, 2016

    Action Type Old Value New Value
    Added Reference http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html [No Types Assigned]
  • CVE Modified by [email protected]

    Nov. 28, 2016

    Action Type Old Value New Value
    Added Reference http://www.securityfocus.com/bid/57778 [No Types Assigned]
  • CVE Modified by [email protected]

    Aug. 23, 2016

    Action Type Old Value New Value
    Added Reference http://marc.info/?l=bugtraq&m=136432043316835&w=2
  • CVE Modified by [email protected]

    Mar. 27, 2015

    Action Type Old Value New Value
    Added Reference http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html
  • Initial Analysis by [email protected]

    Feb. 11, 2013

    Action Type Old Value New Value
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2013-0169 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2013-0169 weaknesses.

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.54 }} 0.00%

score

0.73637

percentile

CVSS2 - Vulnerability Scoring System
Access Vector
Access Complexity
Authentication
Confidentiality
Integrity
Availability