xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xtrabackup | Percona | * | 2.3.5 (including) |
Xtrabackup | Percona | 2.4.0-rc1 (including) | 2.4.0-rc1 (including) |
Xtrabackup | Percona | 2.4.1 (including) | 2.4.1 (including) |
Xtrabackup | Percona | 2.4.2 (including) | 2.4.2 (including) |
Xtrabackup | Percona | 2.4.3 (including) | 2.4.3 (including) |
Xtrabackup | Percona | 2.4.4 (including) | 2.4.4 (including) |
Percona-xtrabackup | Ubuntu | artful | * |
Percona-xtrabackup | Ubuntu | cosmic | * |
Percona-xtrabackup | Ubuntu | disco | * |
Percona-xtrabackup | Ubuntu | eoan | * |
Percona-xtrabackup | Ubuntu | trusty | * |
Percona-xtrabackup | Ubuntu | upstream | * |
Percona-xtrabackup | Ubuntu | xenial | * |
Percona-xtrabackup | Ubuntu | yakkety | * |
Percona-xtrabackup | Ubuntu | zesty | * |