CVE-2012-3458

medium
Published 2022-05-17 ยท Modified 2024-05-01
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2012-3458 NameCVE-2012-3458 DescriptionBeaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search,โ€ฆ

CVE-2012-3458

NameCVE-2012-3458
DescriptionBeaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2541-1
Debian Bugs684890

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
beaker (PTS)bullseye1.11.0-1.1fixed
bookworm1.11.0-3fixed
trixie1.13.0-1fixed
forky, sid1.13.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
beakersourcesqueeze1.5.4-4+squeeze1DSA-2541-1
beakersource(unstable)1.6.3-1.1684890

Home - Debian Security - Source (Git)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.6.3-1.1
sid Fixed 1.6.3-1.1
forky Fixed 1.6.3-1.1
bullseye Fixed 1.6.3-1.1
bookworm Fixed 1.6.3-1.1

Package impact

EcosystemPackageVulnerableFixed
python PyPIbeaker<1.6.41.6.4
python PyPIbeaker<91becae76101cf87ce8cbfabe3af2622fc328fe5||<1.6.5.post191becae76101cf87ce8cbfabe3af2622fc328fe5

Application impact

VendorProductVersionsFixed
python pythonbeaker{"endIncluding":"1.6.4"}

References

CWEs

CWE-310

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.