Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 469044 - <app-emulation/virtualbox-extpack-oracle-4.1.26 : TLS CBC Ciphersuite Plaintext Recovery Weakness (CVE-2013-0169)
Summary: <app-emulation/virtualbox-extpack-oracle-4.1.26 : TLS CBC Ciphersuite Plainte...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53352/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-08 12:48 UTC by Agostino Sarubbo
Modified: 2013-09-04 06:38 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-08 12:48:45 UTC
From ${URL} :

Description
A weakness has been reported in Oracle VirtualBox Extension Pack, which can be exploited by malicious people to disclose certain sensitive information.

The weakness is caused due to the CBC ciphersuite of the Transport Layer Security (TLS) implementation exposing timing differences when verifying the padding checks. This 
can be exploited to recover parts of the plaintext via a timing attack.

The vulnerability is reported in versions 4.2 prior to 4.2.12 and 4.1 prior to 4.1.26.


Solution
Update to version 4.2.12 or 4.1.26.
Original Advisory
https://blogs.oracle.com/sunsecurity/entry/cve_2013_0169_lucky_thirteen


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2013-05-08 12:56:31 UTC
As I said in IRC both versions are already in the tree.
But we will stabilize the 4.1.26 series which consists of the following packages:

~app-emulation/virtualbox-4.1.26
~app-emulation/virtualbox-additions-4.1.26
~app-emulation/virtualbox-bin-4.1.26
~app-emulation/virtualbox-extpack-oracle-4.1.26
~app-emulation/virtualbox-guest-additions-4.1.26
~app-emulation/virtualbox-modules-4.1.26
~x11-drivers/xf86-video-virtualbox-4.1.26

4.2.x still isn't ready for stabilization yet.
4.1.x is quite stable and should IMHO not contain any surprises for our users.

@security: you have my go to process this bug as you think is best.
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2013-05-21 14:26:40 UTC
No action from security so let's process this one...

Arches please test and mark stable the packages mentioned in comment #1

Target keywords for all packages are:

amd64 x86
Comment 3 Agostino Sarubbo gentoo-dev 2013-05-23 17:54:53 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-05-23 17:56:39 UTC
x86 stable
Comment 5 Chris Reffett (RETIRED) gentoo-dev Security 2013-08-27 22:07:34 UTC
GLSA vote: no.
Comment 6 Sergey Popov gentoo-dev 2013-09-04 06:38:50 UTC
GLSA vote: no

Closing as noglsa