xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5...
Vulnerability Description
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-6225
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/percona/percona-xtrabackup/pull/267
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00126.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00125.html
- https://bugs.launchpad.net/percona-xtrabackup/+bug/1643949
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBVCP6KLFVGG6HSGLHLTMZRD6C4IJSZP/
- https://github.com/percona/percona-xtrabackup/pull/266
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAHI6ETS22FJCMLW7A6SICFKQXF5G2VI/
- https://www.percona.com/blog/2017/01/12/cve-2016-6225-percona-xtrabackup-encryption-iv-not-set-properly/
More from percona
View All →Affected Vendor
percona
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.