CVE-2016-6225
23.03.2017, 16:59
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.Enginsight
Vendor | Product | Version |
---|---|---|
percona | xtrabackup | 𝑥 ≤ 2.3.5 |
percona | xtrabackup | 2.4.0:rc1 |
percona | xtrabackup | 2.4.1 |
percona | xtrabackup | 2.4.2 |
percona | xtrabackup | 2.4.3 |
percona | xtrabackup | 2.4.4 |
opensuse | leap | 42.1 |
opensuse | leap | 42.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References