2.1
CVSSv2

CVE-2013-6394

Published: 13/12/2013 Updated: 30/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Percona XtraBackup prior to 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

percona xtrabackup 2.1.1

percona xtrabackup 2.1.0

percona xtrabackup

percona xtrabackup 2.1.4

percona xtrabackup 2.1.3

percona xtrabackup 2.1.2

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #730544 percona-xtrabackup: CVE-2013-6394: static IV used in Percona XtraBackup Package: percona-xtrabackup; Maintainer for percona-xtrabackup is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Source for percona-xtrabackup is src:percona-xtrabackup (PTS, buildd, popcon) Reported ...