First published: Thu Mar 14 2013(Updated: )
A new attack was discovered against TLS that allows an attacker to recover a limited amount of plaintext from a TLS connection when RC4 encryption is used. The attacks arise from statistical flaws in the keystream generated by the RC4 algorithm which become apparent in TLS ciphertexts when the same plaintext is repeatedly encrypted at a fixed location across many TLS sessions. Reference: <a href="http://www.isg.rhul.ac.uk/tls/">http://www.isg.rhul.ac.uk/tls/</a> <a href="http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html">http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Communications Application Session Controller | >=3.0.0<=3.9.1 | |
Oracle HTTP Server | =11.1.1.7.0 | |
Oracle HTTP Server | =11.1.1.9.0 | |
Oracle HTTP Server | =12.1.3.0.0 | |
Oracle HTTP Server | =12.2.1.1.0 | |
Oracle HTTP Server | =12.2.1.2.0 | |
Oracle Integrated Lights Out Manager Firmware | >=3.0.0<=3.2.11 | |
Oracle Integrated Lights Out Manager Firmware | >=4.0.0<=4.0.4 | |
Fujitsu Sparc Enterprise M3000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M3000 | ||
Fujitsu Sparc Enterprise M4000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M4000 | ||
Fujitsu Sparc Enterprise M5000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M5000 | ||
Fujitsu Sparc Enterprise M8000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M8000 | ||
Fujitsu Sparc Enterprise M9000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M9000 | ||
Fujitsu M10-1 Firmware | >=xcp<xcp2280 | |
Fujitsu M10-1 | ||
Fujitsu M10-4 Firmware | >=xcp<xcp2280 | |
Fujitsu M10-4 | ||
Fujitsu M10-4s Firmware | >=xcp<xcp2280 | |
Fujitsu M10-4s | ||
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.04 | |
Canonical Ubuntu Linux | =13.10 | |
Mozilla Firefox | <25.0.1 | |
Mozilla Firefox ESR | <17.0.11 | |
Mozilla Firefox ESR | >=24.1.0<24.1.1 | |
Mozilla SeaMonkey | <2.22.1 | |
Mozilla Thunderbird | <24.1.1 | |
Mozilla Thunderbird Esr | <17.0.11 | |
GE Weakness in UR bootloader binary: all bootloader versions prior to 7.03/7.04 | ||
All of | ||
Fujitsu Sparc Enterprise M3000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M3000 | ||
All of | ||
Fujitsu Sparc Enterprise M4000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M4000 | ||
All of | ||
Fujitsu Sparc Enterprise M5000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M5000 | ||
All of | ||
Fujitsu Sparc Enterprise M8000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M8000 | ||
All of | ||
Fujitsu Sparc Enterprise M9000 Firmware | >=xcp<xcp_1121 | |
Fujitsu Sparc Enterprise M9000 | ||
All of | ||
Fujitsu M10-1 Firmware | >=xcp<xcp2280 | |
Fujitsu M10-1 | ||
All of | ||
Fujitsu M10-4 Firmware | >=xcp<xcp2280 | |
Fujitsu M10-4 | ||
All of | ||
Fujitsu M10-4s Firmware | >=xcp<xcp2280 | |
Fujitsu M10-4s | ||
Mozilla Firefox | <17.0.11 | |
Mozilla Firefox | >=24.1.0<24.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.