Skip to content

LUCKY13 (CVE-2013-0169), experimental : is the issue FP? #1011

Closed
@samvejha

Description

@samvejha

Please find the details about the issue "LUCKY13 (CVE-2013-0169), experimental potentially VULNERABLE, uses cipher block chaining (CBC) ciphers with TLS. Check patches" while openssl version seems to have fixed it.

  1. testssl version from the banner (testssl.sh -b 2>/dev/null | head -4 | tail -2)
    2.9dev from https://testssl.sh/dev/
  2. what exactly was happening, output is needed
    LUCKY13 (CVE-2013-0169), experimental potentially VULNERABLE, uses cipher block chaining (CBC) ciphers with TLS. Check patches
  3. what did you expect instead?
    LUCKY13 Not vulnerable
  4. steps to reproduce
    1. testssl.sh command line
      ./testssl.sh :
    2. openssl version used (testssl.sh -b 2>/dev/null | head -16 | tail -3)
      OpenSSL 1.0.1e-fips 11 Feb 2013
    3. your operating system (uname -a)
      Linux GNU/Linux

-Thanks
Samvedna

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions