CVE-2016-6225
Description
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| suse | 42.1 | affected | |
| suse | 42.2 | affected | |
| fedora | 24 | affected | |
| fedora | 25 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| percona | xtrabackup | {"endIncluding":"2.3.5"} | |
| percona | xtrabackup | 2.4.0 | |
| percona | xtrabackup | 2.4.1 | |
| percona | xtrabackup | 2.4.2 | |
| percona | xtrabackup | 2.4.3 | |
| percona | xtrabackup | 2.4.4 | |
References
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00125.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00126.html
- https://bugs.launchpad.net/percona-xtrabackup/+bug/1643949
- https://github.com/percona/percona-xtrabackup/pull/266
- https://github.com/percona/percona-xtrabackup/pull/267
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAHI6ETS22FJCMLW7A6SICFKQXF5G2VI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBVCP6KLFVGG6HSGLHLTMZRD6C4IJSZP/
- https://www.percona.com/blog/2017/01/12/cve-2016-6225-percona-xtrabackup-encryption-iv-not-set-properly/
- https://www.suse.com/security/cve/CVE-2016-6225.html
CWEs
CWE-326
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.