PT-2012-4731 · Pycrypto+1 · Pycrypto+1

Vincent Danen

·

Publicado

2012-09-15

·

Atualizado

2024-06-15

·

CVE-2012-3458

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Beaker versions prior to 1.6.4
Description The issue allows remote attackers to potentially obtain portions of sensitive session data. This is due to the use of AES in ECB cipher mode when PyCrypto is used to encrypt sessions.
Recommendations For versions prior to 1.6.4, update to version 1.6.4 or later to resolve the issue.

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3458
DSA-2541-1
GHSA-39VM-P9MR-4R27
OPENSUSE-SU-2024:10317-1
OPENSUSE-SU-2024:11203-1
OPENSUSE-SU-2024:13886-1
PYSEC-2012-1

Produtos afetados

Beaker
Pycrypto