Solution
Please Install the Updated Packages.
Insight
Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used in NSS was vulnerable to a timing side-channel attack known as the "
Lucky Thirteen"
issue. A remote attacker could use this issue to perform plaintext-recovery attacks via analysis of timing data.
Affected
nss on Ubuntu 12.10 ,
Ubuntu 12.04 LTS ,
Ubuntu 11.10 ,
Ubuntu 10.04 LTS
Severity
Classification
-
CVE CVE-2013-1620 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
Related Vulnerabilities