xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "percona-xtrabackup", "binary_version": "2.3.7-0ubuntu0.16.04.1" }, { "binary_name": "percona-xtrabackup-dbg", "binary_version": "2.3.7-0ubuntu0.16.04.1" }, { "binary_name": "percona-xtrabackup-dbgsym", "binary_version": "2.3.7-0ubuntu0.16.04.1" }, { "binary_name": "percona-xtrabackup-test", "binary_version": "2.3.7-0ubuntu0.16.04.1" }, { "binary_name": "percona-xtrabackup-test-dbgsym", "binary_version": "2.3.7-0ubuntu0.16.04.1" }, { "binary_name": "xtrabackup", "binary_version": "2.3.7-0ubuntu0.16.04.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "percona-xtrabackup", "binary_version": "2.3.10-0ubuntu1" }, { "binary_name": "percona-xtrabackup-dbg", "binary_version": "2.3.10-0ubuntu1" }, { "binary_name": "percona-xtrabackup-test", "binary_version": "2.3.10-0ubuntu1" }, { "binary_name": "xtrabackup", "binary_version": "2.3.10-0ubuntu1" } ] }