CVE-2013-6450: Medium severity OpenSSL OpenSSL vulnerability
The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1both.c and ssl/t1enc.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6450?
CVE-2013-6450 is considered a high-severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2013-6450?
To fix CVE-2013-6450, upgrade OpenSSL to version 1.0.0l or 1.0.1f or later versions.
Which versions of OpenSSL are affected by CVE-2013-6450?
CVE-2013-6450 affects OpenSSL versions 1.0.0 through 1.0.0h and versions 1.0.1 through 1.0.1e.
What types of attacks can exploit CVE-2013-6450?
CVE-2013-6450 can be exploited by man-in-the-middle attackers to trigger denial of service conditions.
Is there a workaround for CVE-2013-6450?
There are no known effective workarounds for CVE-2013-6450; upgrading is the recommended solution.