Cryptographic issues in OpenSSL - CVE-2013-6450

 

Cryptographic issues in OpenSSL - CVE-2013-6450

Published: January 1, 2014 / Updated: July 28, 2020


Vulnerability identifier: #VU32590
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6450
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.


Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
Slackware Linux
openssl (Alpine package)
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2

How to mitigate CVE-2013-6450

Install update from vendor's website.

OpenSSL - update to 1.0.0l
openssl (Alpine package) - update to 1.0.1f-r0
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2

External References

Related Security Bulletins