CVE-2013-2566: Canonical Ubuntu Linux

Medium severity, CVSS 5.9. EPSS: 84.4% chance of exploitation in the next 30 days.

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only; version 13.10 only
  • Fujitsu m10-1 Firmware: from xcp, before xcp2280 (fixed in xcp2280)
  • Fujitsu m10-4 Firmware: from xcp, before xcp2280 (fixed in xcp2280)
  • Fujitsu m10-4s Firmware: from xcp, before xcp2280 (fixed in xcp2280)
  • Fujitsu Sparc Enterprise m3000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
  • Fujitsu Sparc Enterprise m4000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
  • Fujitsu Sparc Enterprise m5000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
  • Fujitsu Sparc Enterprise m8000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
  • Fujitsu Sparc Enterprise m9000 Firmware: from xcp, before xcp_1121 (fixed in xcp_1121)
  • Mozilla Firefox: before 17.0.11 (fixed in 17.0.11); before 25.0.1 (fixed in 25.0.1); from 24.1.0, before 24.1.1 (fixed in 24.1.1)
  • Mozilla Seamonkey: before 2.22.1 (fixed in 2.22.1)
  • Mozilla Thunderbird: before 24.1.1 (fixed in 24.1.1)
  • Mozilla Thunderbird ESR: before 17.0.11 (fixed in 17.0.11)
  • Oracle Communications Application Session Controller: from 3.0.0, up to and including 3.9.1
  • Oracle HTTP Server: version 11.1.1.7.0 only; version 11.1.1.9.0 only; version 12.1.3.0.0 only; version 12.2.1.1.0 only; version 12.2.1.2.0 only
  • Oracle Integrated Lights Out Manager Firmware: from 3.0.0, up to and including 3.2.11; from 4.0.0, up to and including 4.0.4

Published 2013-03-15. Last modified 2026-06-16.