Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-3458 | First vendor Publication | 2012-09-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3458 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-310 | Cryptographic Issues |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20131 | |||
Oval ID: | oval:org.mitre.oval:def:20131 | ||
Title: | DSA-2541-1 beaker - information disclosure | ||
Description: | It was discovered that Beaker, a cache and session library for Python, when using the python-crypto backend, is vulnerable to information disclosure due to a cryptographic weakness related to the use of the AES cipher in ECB mode. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2541-1 CVE-2012-3458 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | beaker |
Definition Synopsis: | |||
|
OpenVAS Exploits
Date | Description |
---|---|
2012-09-15 | Name : Debian Security Advisory DSA 2541-1 (beaker) File : nvt/deb_2541_1.nasl |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-09-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2541.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 22:59:57 |
|
2024-11-28 12:30:44 |
|
2021-04-22 01:25:13 |
|
2020-05-23 01:49:14 |
|
2020-05-23 00:34:11 |
|
2016-04-26 22:04:59 |
|
2014-02-17 11:11:45 |
|
2013-05-10 22:42:34 |
|