PT-2025-9525 · Aes-Gcm · Aes-Gcm
Thealtofwar
·
Publicado
2025-03-03
·
Atualizado
2025-03-04
·
CVE-2025-27498
CVSS v4.0
5.6
Média
| Vetor | AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
aes-gcm versions prior to 0.4.3
Description
The issue arises in the decrypt in place detached function, where the decrypted ciphertext is exposed even if the tag is incorrect. This occurs because the tag verification in the decrypt inplace function returns an error with the plaintext contents still in the buffer.
Recommendations
For versions prior to 0.4.3, update to version 0.4.3 to resolve the issue.
Exploit
Correção
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aes-Gcm