Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Elixir | Ematia | 0.8.0 (including) | 0.8.0 (including) |
Elixir | Ubuntu | artful | * |
Elixir | Ubuntu | hardy | * |
Elixir | Ubuntu | lucid | * |
Elixir | Ubuntu | natty | * |
Elixir | Ubuntu | oneiric | * |
Elixir | Ubuntu | precise | * |
Elixir | Ubuntu | quantal | * |
Elixir | Ubuntu | raring | * |
Elixir | Ubuntu | saucy | * |
Elixir | Ubuntu | trusty | * |
Elixir | Ubuntu | upstream | * |
Elixir | Ubuntu | utopic | * |
Elixir | Ubuntu | vivid | * |
Elixir | Ubuntu | wily | * |
Elixir | Ubuntu | xenial | * |
Elixir | Ubuntu | yakkety | * |
Elixir | Ubuntu | zesty | * |