CVE-2016-6225

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
23/03/2017
Last modified:
20/04/2025

Description

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:percona:xtrabackup:*:*:*:*:*:*:*:* 2.3.5 (including)
cpe:2.3:a:percona:xtrabackup:2.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:percona:xtrabackup:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:percona:xtrabackup:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:percona:xtrabackup:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:percona:xtrabackup:2.4.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*