PT-2025-9525 · Aes-Gcm · Aes-Gcm

Thealtofwar

·

Publicado

2025-03-03

·

Atualizado

2025-03-04

·

CVE-2025-27498

CVSS v4.0

5.6

Média

VetorAV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aes-gcm versions prior to 0.4.3
Description The issue arises in the decrypt in place detached function, where the decrypted ciphertext is exposed even if the tag is incorrect. This occurs because the tag verification in the decrypt inplace function returns an error with the plaintext contents still in the buffer.
Recommendations For versions prior to 0.4.3, update to version 0.4.3 to resolve the issue.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-27498
GHSA-R38M-44FW-H886

Produtos afetados

Aes-Gcm