Bug#699888: TLS timing attack in nss (Lucky 13)

2013-02-24 Thread Thijs Kinkhorst
Hi, For the record, this is fixed in upstream release 3.14.3. https://developer.mozilla.org/en-US/docs/NSS/NSS_3.14.3_release_notes Cheers, Thijs signature.asc Description: This is a digitally signed message part.

Bug#699888: TLS timing attack in nss (Lucky 13)

2013-02-06 Thread Thijs Kinkhorst
Package: nss Severity: serious Tags: security Hi, Nadhem Alfardan and Kenny Paterson have discovered a weakness in the handling of CBC ciphersuites in SSL, TLS and DTLS. Their attack exploits timing differences arising during MAC processing. Details of this attack can be found at: http://www.isg.