Описание
Beaker Sensitive Information Disclosure vulnerability
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-3458
- https://github.com/bbangert/beaker/commit/91becae76101cf87ce8cbfabe3af2622fc328fe5
- https://bugzilla.redhat.com/show_bug.cgi?id=809267
- https://github.com/pypa/advisory-database/tree/main/vulns/beaker/PYSEC-2012-1.yaml
- https://web.archive.org/web/20140724164516/http://secunia.com/advisories/50226
- https://web.archive.org/web/20140725025612/http://secunia.com/advisories/50520
- http://www.debian.org/security/2012/dsa-2541
- http://www.openwall.com/lists/oss-security/2012/08/13/10
Пакеты
beaker
< 1.6.4
1.6.4
Связанные уязвимости
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES ...