The TLS and DTLS protocols are vulnerable to an information disclosure weakness. The issue is due to a distinguishing attack against the MEE-TLS-CBC ciphersuite construction as used in TLS / DTLS. This form of cryptanalysis allows an attacker to choose pairs of messages, one encrypted, one the resulting ciphertext, to determine specific information about the messages. This may allow them to distinguish the traffic from random data, making subsequent cryptanalysis more efficient. In addition, this may also allow the attacker to determine the encryption method used, some information about the encrypted message, or ultimately narrow the key space.