CWE-208: Timing Discrepancy Information Leak
Timing Discrepancy Information Leak
Weakness ID: 208 (Weakness Base) Status: Incomplete
Description
Description Summary
Two separate operations in a product require different amounts
of time to complete, in a way that is observable to an actor and reveals
security-relevant information about the state of the product, such as whether a
particular operation was successful or not.
Time of Introduction
Architecture and Design
Implementation
Operation
Observed Examples
Other Notes
Relationships
Relationship Notes
Often primary in cryptographic applications and algorithms.
Functional Areas
Cryptography, authentication
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Timing discrepancy infoleak
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships, Other Notes, Relationship Notes,
Taxonomy Mappings 2008-10-14 CWE Content Team MITRE Internal updated Description