xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
| Software | From | Fixed in |
|---|---|---|
| percona / xtrabackup | - | 2.3.5.x |
| percona / xtrabackup | 2.4.1 | 2.4.1.x |
| percona / xtrabackup | 2.4.0-rc1 | 2.4.0-rc1.x |
| percona / xtrabackup | 2.4.3 | 2.4.3.x |
| percona / xtrabackup | 2.4.2 | 2.4.2.x |
| percona / xtrabackup | 2.4.4 | 2.4.4.x |
| opensuse / leap | 42.2 | 42.2.x |
| opensuse / leap | 42.1 | 42.1.x |
| fedoraproject / fedora | 25 | 25.x |
| fedoraproject / fedora | 24 | 24.x |