CVE-2012-3458

Publication date 15 September 2012

Last updated 24 July 2024


Ubuntu priority

Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.

Status

Package Ubuntu Release Status
beaker 16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.10 utopic Ignored end of life
14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
13.04 raring Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise
Fixed 1.5.4-4+squeeze1build0.12.04.1
11.10 oneiric
Fixed 1.5.4-4+squeeze1build0.11.10.1
11.04 natty
Fixed 1.5.4-4+squeeze1build0.11.04.1
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
beaker