ZeroHour

CVE-2016-6225

CVSS 3.0
5.9 medium
EPSS
1%p64
Published
()
Modified
Description

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Vendors
perconaopensusefedoraproject
Products
xtrabackup, leap, fedora
Weakness
CWE-326
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.