Cryptographic issues in xtrabackup - CVE-2013-6394

 

Cryptographic issues in xtrabackup - CVE-2013-6394

Published: December 13, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32494
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6394
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to manipulate data.

Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.


Affected software

xtrabackup
xtrabackup (Alpine package)

How to mitigate CVE-2013-6394

Install update from vendor's website.

xtrabackup (Alpine package) - update to 2.1.9-r0

External References

Related Security Bulletins