Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 455766 (CVE-2013-1623)

Summary: <net-libs/cyassl-2.5.0: TLS CBC timing vulnerability (CVE-2013-1623)
Product: Gentoo Security Reporter: Hanno Böck <hanno>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: blueness
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.isg.rhul.ac.uk/tls/
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 421465    
Bug Blocks:    

Description Hanno Böck gentoo-dev 2013-02-06 00:25:56 UTC
See
http://www.isg.rhul.ac.uk/tls/

cyassl suffers (as most ssl implementations) from a CBC timing attack. Mitigation measures are implemented in version 2.5.0.
Comment 1 Anthony Basile gentoo-dev 2013-02-06 02:36:43 UTC
Unfortunately cyassl-2.5.0 requires automake 1.12. A simple backport to 1.11 fails.  I'll get it ready with WANT_AUTOMAKE=1.12 but we may have to want to put pressure on automake.  This is now a well known vuln.
Comment 2 Anthony Basile gentoo-dev 2013-02-06 03:07:26 UTC
+*cyassl-2.5.0 (06 Feb 2013)
+
+  06 Feb 2013; Anthony G. Basile <blueness@gentoo.org> +cyassl-2.5.0.ebuild,
+  metadata.xml:
+  Version bump, sercurity fix, bug #455766
+
Comment 3 Anthony Basile gentoo-dev 2013-02-12 00:33:00 UTC
(In reply to comment #1)
> Unfortunately cyassl-2.5.0 requires automake 1.12. A simple backport to 1.11
> fails.  I'll get it ready with WANT_AUTOMAKE=1.12 but we may have to want to
> put pressure on automake.  This is now a well known vuln.

I found a workaround in the build system so that the ebuild does not depend on automake 11.12.  We're good to go for rapid stabilization.

Please stabilize =net-libs/cyassl-2.5.0.  TARGET"amd64 arm hppa ppc ppc64 x86"
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2013-02-13 02:12:32 UTC
Stable for HPPA.
Comment 5 Agostino Sarubbo gentoo-dev 2013-02-13 16:50:59 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-02-13 16:53:26 UTC
ppc64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-02-14 13:08:29 UTC
amd64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-02-14 13:10:00 UTC
x86 stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-02-22 18:41:47 UTC
arm stable
Comment 10 Sean Amoss (RETIRED) gentoo-dev Security 2013-02-25 22:34:36 UTC
GLSA vote: no.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2013-03-04 23:38:46 UTC
CVE-2013-1623 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1623):
  The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not
  properly consider timing side-channel attacks on a noncompliant MAC check
  operation during the processing of malformed CBC padding, which allows
  remote attackers to conduct distinguishing attacks and plaintext-recovery
  attacks via statistical analysis of timing data for crafted packets, a
  related issue to CVE-2013-0169.
Comment 12 Sergey Popov gentoo-dev 2013-08-22 10:31:53 UTC
GLSA vote: no

Closing as noglsa