CVE-2013-6394
published 2013-12-13CVE-2013-6394: Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic…
PriorityP43low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.38%
30.3th percentile
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| percona | xtrabackup | <= 2.3.5 | — |
| percona | xtrabackup | <= 2.1.5 | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
| percona | xtrabackup | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgjv-rwc2-2rr2: xbcrypt in Percona XtraBackup before 2
ghsa_unreviewed·2022-05-14·CVSS 2.1
CVE-2016-6225 [LOW] CWE-326 GHSA-qgjv-rwc2-2rr2: xbcrypt in Percona XtraBackup before 2
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
GHSA
GHSA-f2mj-h98v-gmcf: Percona XtraBackup before 2
ghsa_unreviewed·2022-05-14
CVE-2013-6394 [LOW] GHSA-f2mj-h98v-gmcf: Percona XtraBackup before 2
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.
OSV
CVE-2016-6225: xbcrypt in Percona XtraBackup before 2
osv·2017-03-23·CVSS 2.1
CVE-2016-6225 [LOW] CVE-2016-6225: xbcrypt in Percona XtraBackup before 2
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
OSV
CVE-2013-6394: Percona XtraBackup before 2
osv·2013-12-13·CVSS 2.1
CVE-2013-6394 [LOW] CVE-2013-6394: Percona XtraBackup before 2
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-updates/2013-12/msg00052.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00044.htmlhttp://www.openwall.com/lists/oss-security/2013/11/26/11http://www.percona.com/doc/percona-xtrabackup/2.1/release-notes/2.1/2.1.6.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00052.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00044.htmlhttp://www.openwall.com/lists/oss-security/2013/11/26/11http://www.percona.com/doc/percona-xtrabackup/2.1/release-notes/2.1/2.1.6.html
2013-12-13
Published