CPANSA-Crypt-CBC-2006-0898: Crypt-CBC vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2006-02-25T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2006-02-25T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | ||
Original language | Language | en | |
Also referred to |
Vulnerability Description
Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.
Vulnerabilities
CVE-2006-0898
Vulnerability DescriptionCrypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
Crypt-CBC less than 2.17 |
|
Fixed
- Crypt-CBC greater than or equal 2.17
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Crypt-CBC-2006-0898 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2006/cpansa-crypt-cbc-2006-0898.json - https://metacpan.org/changes/distribution/Crypt-CBC external
https://metacpan.org/changes/distribution/Crypt-CBC - http://www.securityfocus.com/bid/16802 external
http://www.securityfocus.com/bid/16802 - http://secunia.com/advisories/18755 external
http://secunia.com/advisories/18755 - http://www.debian.org/security/2006/dsa-996 external
http://www.debian.org/security/2006/dsa-996 - http://secunia.com/advisories/19187 external
http://secunia.com/advisories/19187 - http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml external
http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml - http://secunia.com/advisories/19303 external
http://secunia.com/advisories/19303 - http://www.novell.com/linux/security/advisories/2006_38_security.html external
http://www.novell.com/linux/security/advisories/2006_38_security.html - http://secunia.com/advisories/20899 external
http://secunia.com/advisories/20899 - http://securityreason.com/securityalert/488 external
http://securityreason.com/securityalert/488 - http://www.redhat.com/support/errata/RHSA-2008-0261.html external
http://www.redhat.com/support/errata/RHSA-2008-0261.html - http://secunia.com/advisories/31493 external
http://secunia.com/advisories/31493 - http://rhn.redhat.com/errata/RHSA-2008-0630.html external
http://rhn.redhat.com/errata/RHSA-2008-0630.html - https://exchange.xforce.ibmcloud.com/vulnerabilities/24954 external
https://exchange.xforce.ibmcloud.com/vulnerabilities/24954 - http://www.securityfocus.com/archive/1/425966/100/0/threaded external
http://www.securityfocus.com/archive/1/425966/100/0/threaded - CVE-2006-0898 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2006-0898
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Sat Feb 25 00:00:00 2006 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/