Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Beaker | Python | * | 1.6.4 (including) |
| Beaker | Ubuntu | hardy | * |
| Beaker | Ubuntu | lucid | * |
| Beaker | Ubuntu | natty | * |
| Beaker | Ubuntu | oneiric | * |
| Beaker | Ubuntu | precise | * |
| Beaker | Ubuntu | quantal | * |
| Beaker | Ubuntu | raring | * |
| Beaker | Ubuntu | saucy | * |
| Beaker | Ubuntu | upstream | * |
| Beaker | Ubuntu | utopic | * |
| Beaker | Ubuntu | vivid | * |
| Beaker | Ubuntu | wily | * |