← Vulnerability feed

Vulnerability record · CVE-2013-0169 · published 8 February 2013

CVE-2013-0169: Openssl vulnerability

OOpenssl · Openssl

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

2.6 CVSS 2.0 Low EPSS 36% · top 1.6% CWE-310 · CWE-310
2.6CVSS 2.0 base score
36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
110References
16 Jun 2026Last modified by NVD

Description

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

AV:N/AC:H/Au:N/C:P/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7-for-openjdk-7-released/ Third Party Advisory
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html Mailing ListThird Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101366.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html Third Party Advisory
http://marc.info/?l=bugtraq&m=136396549913849&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136432043316835&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136439120408139&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=136733161405818&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=137545771702053&w=2 Third Party Advisory
http://openwall.com/lists/oss-security/2013/02/05/24 Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0587.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0782.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0783.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0833.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1456.html Third Party Advisory
http://secunia.com/advisories/53623 Third Party Advisory
http://secunia.com/advisories/55108 Third Party Advisory
http://secunia.com/advisories/55139 Third Party Advisory
http://secunia.com/advisories/55322 Third Party Advisory
http://secunia.com/advisories/55350 Third Party Advisory
http://secunia.com/advisories/55351 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://support.apple.com/kb/HT5880 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21644047 Third Party Advisory
http://www.debian.org/security/2013/dsa-2621 Third Party Advisory
http://www.debian.org/security/2013/dsa-2622 Third Party Advisory
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf Third Party Advisory
http://www.kb.cert.org/vuls/id/737740 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 Third Party Advisory
http://www.matrixssl.org/news.html Third Party Advisory
http://www.openssl.org/news/secadv_20130204.txt Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html Third Party Advisory
http://www.securityfocus.com/bid/57778 Third Party AdvisoryVDB Entry

Track CVE-2013-0169 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed5.3CVE-2013-0431Oracle JRE and OpenJDK JMX sandbox bypassAn unspecified flaw in the Java Runtime Environment (JRE) component of Oracle Java SE 7 through Update 11 and OpenJDK 7 allows a user-assisted remote…KEVEPSS 90%analysed10.0CVE-2014-8873Oracle openjdk improper input validation vulnerabilityA .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, …EPSS 4.5%10.0CVE-2014-2405Oracle openjdk vulnerabilityUnspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a di…EPSS 2.3%10.0CVE-2014-0462Oracle openjdk vulnerabilityUnspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a di…EPSS 2.3%10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2013-0169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.