---
title: "CVE-2013-2566\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-2566?format=md
keywords: index, follow
---

# CVE-2013-2566

Publication date 15 March 2013

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2013-2566?format=md#impact-score)

Toggle side navigation

## Description

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many
single-byte biases, which makes it easier for remote attackers to conduct
plaintext-recovery attacks via statistical analysis of ciphertext in a
large number of sessions that use the same plaintext.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-2566?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 13.10 saucy | Fixed 25.0.1+build1-0ubuntu0.13.10.1 |
| 13.04 raring | Fixed 25.0.1+build1-0ubuntu0.13.04.1 |
| 12.10 quantal | Fixed 25.0.1+build1-0ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 25.0.1+build1-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |
| openssl | 13.10 saucy | Ignored |
| 13.04 raring | Ignored |
| 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Ignored |
| 8.04 LTS hardy | Ignored |
| thunderbird | 13.10 saucy | Fixed 1:24.1.1+build1-0ubuntu0.13.10.1 |
| 13.04 raring | Fixed 1:24.1.1+build1-0ubuntu0.13.04.1 |
| 12.10 quantal | Fixed 1:24.1.1+build1-0ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 1:24.1.1+build1-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

this is a protocol problem not specific to openssl. Using openssl
as a placeholder until more information is available
marking low for now until more information is available. At present,
naive attacks need tens to hundreds of millions of TLS connections. Optimized
attacks are not present yet.
marking deferred since there is no consensus on what to do (we can't
just disable RC4)

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

marking as ignored since there is no actionable item

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2566)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-2566)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-2566)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-2566)

### Related Ubuntu Security Notices (USN)

+ [USN-2031-1](https://usn.ubuntu.com/USN-2031-1)
+ Firefox vulnerabilities
+ 20 November 2013

+ [USN-2032-1](https://usn.ubuntu.com/USN-2032-1)
+ Thunderbird vulnerabilities
+ 21 November 2013

### Other references

* <http://www.isg.rhul.ac.uk/tls/>
* <http://cr.yp.to/talks/2013.03.12/slides.pdf>
* <http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html>
* <http://www.mozilla.org/security/announce/2013/mfsa2013-103.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-2566>
