CVE Vulnerabilities

CVE-2016-6225

Inadequate Encryption Strength

Published: Mar 23, 2017 | Modified: Nov 07, 2023
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Xtrabackup Percona * 2.3.5 (including)
Xtrabackup Percona 2.4.0-rc1 (including) 2.4.0-rc1 (including)
Xtrabackup Percona 2.4.1 (including) 2.4.1 (including)
Xtrabackup Percona 2.4.2 (including) 2.4.2 (including)
Xtrabackup Percona 2.4.3 (including) 2.4.3 (including)
Xtrabackup Percona 2.4.4 (including) 2.4.4 (including)
Percona-xtrabackup Ubuntu artful *
Percona-xtrabackup Ubuntu cosmic *
Percona-xtrabackup Ubuntu disco *
Percona-xtrabackup Ubuntu eoan *
Percona-xtrabackup Ubuntu trusty *
Percona-xtrabackup Ubuntu upstream *
Percona-xtrabackup Ubuntu xenial *
Percona-xtrabackup Ubuntu yakkety *
Percona-xtrabackup Ubuntu zesty *

Potential Mitigations

References