CVE-2016-6225
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via…
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- percona/xtrabackup · opensuse/leap · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00125.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00126.htmlThird Party Advisory
- https://bugs.launchpad.net/percona-xtrabackup/+bug/1643949Issue Tracking, Patch, Third Party Advisory
- https://github.com/percona/percona-xtrabackup/pull/266Issue Tracking, Patch, Third Party Advisory
- https://github.com/percona/percona-xtrabackup/pull/267Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAHI6ETS22FJCMLW7A6SICFKQXF5G2VI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBVCP6KLFVGG6HSGLHLTMZRD6C4IJSZP/
- https://www.percona.com/blog/2017/01/12/cve-2016-6225-percona-xtrabackup-encryption-iv-not-set-properly/Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00125.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00126.htmlThird Party Advisory
- https://bugs.launchpad.net/percona-xtrabackup/+bug/1643949Issue Tracking, Patch, Third Party Advisory
- https://github.com/percona/percona-xtrabackup/pull/266Issue Tracking, Patch, Third Party Advisory
- https://github.com/percona/percona-xtrabackup/pull/267Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAHI6ETS22FJCMLW7A6SICFKQXF5G2VI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBVCP6KLFVGG6HSGLHLTMZRD6C4IJSZP/
- https://www.percona.com/blog/2017/01/12/cve-2016-6225-percona-xtrabackup-encryption-iv-not-set-properly/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.