Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rpicardo

#30339of 53,633
8.7Total CVSS
Vulnerabilities · 1
PT-2017-7269
8.7
2017-08-09
Lemur · Lemur · CVE-2015-7764
**Name of the Vulnerable Software and Affected Versions** Lemur version 0.1.4 **Description** The issue is related to insufficient entropy in the initialization vector (IV) when encrypting AES in CBC mode. **Recommendations** For version 0.1.4, consider updating to a version that properly implements sufficient entropy in its IV for AES encryption in CBC mode. At the moment, there is no information about a newer version that contains a fix for this vulnerability.