PT-2012-4731 · Pycrypto+1 · Pycrypto+1

Vincent Danen

·

Published

2012-09-15

·

Updated

2024-06-15

·

CVE-2012-3458

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Beaker versions prior to 1.6.4
Description The issue allows remote attackers to potentially obtain portions of sensitive session data. This is due to the use of AES in ECB cipher mode when PyCrypto is used to encrypt sessions.
Recommendations For versions prior to 1.6.4, update to version 1.6.4 or later to resolve the issue.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3458
DSA-2541-1
GHSA-39VM-P9MR-4R27
OPENSUSE-SU-2024:10317-1
OPENSUSE-SU-2024:11203-1
OPENSUSE-SU-2024:13886-1
PYSEC-2012-1

Affected Products

Beaker
Pycrypto