Cryptographic issues in xtrabackup - CVE-2013-6394

 

Cryptographic issues in xtrabackup - CVE-2013-6394

Published: December 13, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32494
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-6394
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
xtrabackup
Software vendor:
Percona LLC

Description

The vulnerability allows a local non-authenticated attacker to manipulate data.

Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.


Remediation

Install update from vendor's website.

External links