CVE-2013-0169

NameCVE-2013-0169
DescriptionThe TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as ...
SourceCVE (at NVD; oss-sec, OSVDB, EDB, Red Hat, Ubuntu, Gentoo, SuSE, more)
ReferencesDSA-2621-1, DSA-2622-1
Debian Bugs699885, 699886, 699887, 699888, 699889
Debian/oldstablepackages bouncycastle, mysql-5.1, nss, openjdk-6 are vulnerable.
Debian/stablepackage bouncycastle is vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bouncycastle (PTS)squeeze1.44+dfsg-2vulnerable
wheezy1.44+dfsg-3.1vulnerable
jessie, sid1.49+dfsg-2fixed
mysql-5.1 (PTS)squeeze, squeeze (security)5.1.73-1vulnerable
mysql-5.5 (PTS)wheezy5.5.33+dfsg-0+wheezy1fixed
wheezy (security)5.5.35+dfsg-0+wheezy1fixed
jessie, sid5.5.35+dfsg-2fixed
nss (PTS)squeeze, squeeze (security)3.12.8-1+squeeze7vulnerable
wheezy, wheezy (security)2:3.14.5-1fixed
jessie, sid2:3.16-1fixed
openjdk-6 (PTS)squeeze6b18-1.8.13-0+squeeze2vulnerable
wheezy6b27-1.12.5-1fixed
squeeze (security)6b27-1.12.6-1~deb6u1fixed
wheezy (security)6b27-1.12.6-1~deb7u1fixed
jessie, sid6b31-1.13.3-1fixed
openjdk-7 (PTS)wheezy7u3-2.1.7-1fixed
wheezy (security)7u25-2.3.10-1~deb7u1fixed
jessie7u51-2.4.6-1fixed
sid7u55-2.4.7-1fixed
openssl (PTS)squeeze, squeeze (security)0.9.8o-4squeeze14fixed
wheezy1.0.1e-2+deb7u4fixed
wheezy (security)1.0.1e-2+deb7u7fixed
jessie1.0.1g-2fixed
sid1.0.1g-3fixed
polarssl (PTS)squeeze0.12.1-1squeeze1fixed
squeeze (security)1.2.9-1~deb6u1fixed
wheezy, wheezy (security)1.2.9-1~deb7u1fixed
jessie1.3.4-1fixed
sid1.3.6-1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bouncycastlesource(unstable)1.48+dfsg-2low699885
mysql-5.1source(unstable)(unfixed)
mysql-5.5source(unstable)5.5.30+dfsg-1.1699886
nsssource(unstable)2:3.14.3-1699888
openjdk-6source(unstable)6b27-1.12.3-1
openjdk-7source(unstable)7u3-2.1.6-1
opensslsource(unstable)1.0.1e-1699889
opensslsourcesqueeze0.9.8o-4squeeze14DSA-2621-1
polarsslsource(unstable)1.1.4-2699887
polarsslsourcesqueeze0.12.1-1squeeze1DSA-2622-1

Notes

[wheezy] - bouncycastle <no-dsa> (Minor issue)
[squeeze] - bouncycastle <no-dsa> (Minor issue)
[squeeze] - nss <no-dsa> (Minor issue)
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)