Security Advisory

CVE-2013-7463

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-04-19 17:00:00
Last updated 2024-08-06 18:09:16
Assigner mitre
State PUBLISHED

Description

The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.