PT-2025-9525 · Aes-Gcm · Aes-Gcm
Thealtofwar
·
Published
2025-03-03
·
Updated
2025-03-04
·
CVE-2025-27498
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
aes-gcm versions prior to 0.4.3
Description
The issue arises in the decrypt in place detached function, where the decrypted ciphertext is exposed even if the tag is incorrect. This occurs because the tag verification in the decrypt inplace function returns an error with the plaintext contents still in the buffer.
Recommendations
For versions prior to 0.4.3, update to version 0.4.3 to resolve the issue.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aes-Gcm