CVE Database
/

CVE-2013-7463

Back to search

CVE-2013-7463

Published: Apr 19, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

98035
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now