CVE-2017-11133
01.08.2017, 14:29
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used with a pseudo-random secret. This secret and the IV are generated with math.random() in previous versions and with CryptoJS.lib.WordArray.random() in newer versions, which uses math.random() internally. This is not cryptographically strong.Enginsight
Vendor | Product | Version |
---|---|---|
stashcat | heinekingmedia | 𝑥 ≤ 0.0.80w |
stashcat | heinekingmedia | 𝑥 ≤ 0.0.86w |
𝑥
= Vulnerable software versions
Common Weakness Enumeration