All errata/sisyphus/ALT-PU-2017-3601-1
ALT-PU-2017-3601-1

Package update percona-xtrabackup in branch sisyphus

Version2.4.5-alt2
Published2017-02-06
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2016-6225
MEDIUM5.9

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Published: 2017-03-23Modified: 2025-04-20
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 5.9
CVSS:3.x/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N