[Bug 430522] New: CVE-2006-0898 perl-Crypt-CBC weaker encryption with some ciphers

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.




https://bugzilla.redhat.com/show_bug.cgi?id=430522

           Summary: CVE-2006-0898 perl-Crypt-CBC weaker encryption with some
                    ciphers
           Product: Security Response
           Version: unspecified
          Platform: All
               URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-0898
        OS/Version: Linux
            Status: NEW
          Severity: low
          Priority: low
         Component: vulnerability
        AssignedTo: security-response-team@xxxxxxxxxx
        ReportedBy: mjc@xxxxxxxxxx
                CC: andreas@xxxxxxxxx,fedora-perl-devel-list@xxxxxxxxxx


Common Vulnerabilities and Exposures assigned an identifier CVE-2006-0898 to the following vulnerability:

Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.

References:

http://www.securityfocus.com/archive/1/archive/1/425966/100/0/threaded
http://www.debian.org/security/2006/dsa-996
http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml
http://www.novell.com/linux/security/advisories/2006_38_security.html
http://www.securityfocus.com/bid/16802
http://secunia.com/advisories/18755
http://secunia.com/advisories/19187
http://secunia.com/advisories/19303
http://secunia.com/advisories/20899
http://securityreason.com/securityalert/488
http://xforce.iss.net/xforce/xfdb/24954

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.

--
Fedora Extras Perl SIG
http://www.fedoraproject.org/wiki/Extras/SIGs/Perl
Fedora-perl-devel-list mailing list
Fedora-perl-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-perl-devel-list

[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite Information]
  Powered by Linux