Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 455766 (CVE-2013-1623) - <net-libs/cyassl-2.5.0: TLS CBC timing vulnerability (CVE-2013-1623)
Summary: <net-libs/cyassl-2.5.0: TLS CBC timing vulnerability (CVE-2013-1623)
Status: RESOLVED FIXED
Alias: CVE-2013-1623
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.isg.rhul.ac.uk/tls/
Whiteboard: B3 [noglsa]
Keywords:
Depends on: automake-1.12
Blocks:
  Show dependency tree
 
Reported: 2013-02-06 00:25 UTC by Hanno Böck
Modified: 2013-08-22 10:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2013-02-06 00:25:56 UTC
See
http://www.isg.rhul.ac.uk/tls/

cyassl suffers (as most ssl implementations) from a CBC timing attack. Mitigation measures are implemented in version 2.5.0.
Comment 1 Anthony Basile gentoo-dev 2013-02-06 02:36:43 UTC
Unfortunately cyassl-2.5.0 requires automake 1.12. A simple backport to 1.11 fails.  I'll get it ready with WANT_AUTOMAKE=1.12 but we may have to want to put pressure on automake.  This is now a well known vuln.
Comment 2 Anthony Basile gentoo-dev 2013-02-06 03:07:26 UTC
+*cyassl-2.5.0 (06 Feb 2013)
+
+  06 Feb 2013; Anthony G. Basile <blueness@gentoo.org> +cyassl-2.5.0.ebuild,
+  metadata.xml:
+  Version bump, sercurity fix, bug #455766
+
Comment 3 Anthony Basile gentoo-dev 2013-02-12 00:33:00 UTC
(In reply to comment #1)
> Unfortunately cyassl-2.5.0 requires automake 1.12. A simple backport to 1.11
> fails.  I'll get it ready with WANT_AUTOMAKE=1.12 but we may have to want to
> put pressure on automake.  This is now a well known vuln.

I found a workaround in the build system so that the ebuild does not depend on automake 11.12.  We're good to go for rapid stabilization.

Please stabilize =net-libs/cyassl-2.5.0.  TARGET"amd64 arm hppa ppc ppc64 x86"
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2013-02-13 02:12:32 UTC
Stable for HPPA.
Comment 5 Agostino Sarubbo gentoo-dev 2013-02-13 16:50:59 UTC
ppc stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-02-13 16:53:26 UTC
ppc64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-02-14 13:08:29 UTC
amd64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-02-14 13:10:00 UTC
x86 stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-02-22 18:41:47 UTC
arm stable
Comment 10 Sean Amoss (RETIRED) gentoo-dev Security 2013-02-25 22:34:36 UTC
GLSA vote: no.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2013-03-04 23:38:46 UTC
CVE-2013-1623 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1623):
  The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not
  properly consider timing side-channel attacks on a noncompliant MAC check
  operation during the processing of malformed CBC padding, which allows
  remote attackers to conduct distinguishing attacks and plaintext-recovery
  attacks via statistical analysis of timing data for crafted packets, a
  related issue to CVE-2013-0169.
Comment 12 Sergey Popov gentoo-dev 2013-08-22 10:31:53 UTC
GLSA vote: no

Closing as noglsa