Security readout for executives and security teams
CVE-2013-1619 is a GnuTLS flaw where tiny timing differences during TLS error handling could leak information about encrypted traffic. It affects older GnuTLS releases before 2.12.23, 3.0.28, and 3.1.7. The business risk is highest for legacy systems still depending on these versions. Exposure is likely limited to systems, appliances, or applications using vulnerable GnuTLS versions for TLS. Prioritize internet-facing services, security gateways, mail, package repositories, and embedded or long-lived Linux deployments that may retain old libraries. Treat this as a legacy TLS hygiene issue with confidentiality impact. It should not displace emergency patching without active exploitation evidence, but any exposed or sensitive system still running affected GnuTLS should be updated in the next maintenance cycle. Mitigation focus: Upgrade GnuTLS to 2.12.23, 3.0.28, 3.1.7, or later as applicable.; Apply distribution vendor updates from Ubuntu, Red Hat, SUSE, or the relevant package maintainer.; Prioritize internet-facing systems and services handling sensitive authenticated sessions..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-1619 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://gitorious.org/gnutls/gnutls/commit/328ee22c1b3951e060c7124c7cb1cee592c59bc0CVE reference · x_refsource_CONFIRM
- https://gitorious.org/gnutls/gnutls/commit/b8391806cd79095fe566f2401d8c7ad85a64b198CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
