External check

2017-01-13 Thread Raphael Geissert
CVE-2016-10141: missing from list -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was run.

Re: CVE-2016-6225 percona-xtrabackup Encryption IV Not Being Set Properly

2017-01-13 Thread Salvatore Bonaccorso
Hi, On Fri, Jan 13, 2017 at 09:28:30AM +, David Busby wrote: > Dear Debian Maintainers, > > Please note percona-xtrabackup < 2.3.6 && < 2.4.5 is vulnerable to a > Chosen-Plaintext attack when running xbcrypt to encrypt backups. > > Backup plaintext data can be retrieved in this manner withou

CVE-2016-6225 percona-xtrabackup Encryption IV Not Being Set Properly

2017-01-13 Thread David Busby
Dear Debian Maintainers, Please note percona-xtrabackup < 2.3.6 && < 2.4.5 is vulnerable to a Chosen-Plaintext attack when running xbcrypt to encrypt backups. Backup plaintext data can be retrieved in this manner without the original password. We have blogged about the fix for the issue here