{"id":"CVE-2016-6225","details":"xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.","modified":"2026-07-08T05:50:45.310499840Z","published":"2017-03-23T16:59:00.247Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"24"},{"last_affected":"24"},{"introduced":"25"},{"last_affected":"25"}]},{"cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"},{"introduced":"42.2"},{"last_affected":"42.2"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAHI6ETS22FJCMLW7A6SICFKQXF5G2VI/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBVCP6KLFVGG6HSGLHLTMZRD6C4IJSZP/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00125.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00126.html"},{"type":"ADVISORY","url":"https://www.percona.com/blog/2017/01/12/cve-2016-6225-percona-xtrabackup-encryption-iv-not-set-properly/"},{"type":"FIX","url":"https://bugs.launchpad.net/percona-xtrabackup/+bug/1643949"},{"type":"FIX","url":"https://github.com/percona/percona-xtrabackup/pull/266"},{"type":"FIX","url":"https://github.com/percona/percona-xtrabackup/pull/267"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/percona/percona-xtrabackup","events":[{"introduced":"0"},{"last_affected":"45cda897da4c6be5ce0bce127e7a1933229d4d16"},{"introduced":"0d1198401797ef6f29ddc4604a5ce585ef476106"},{"last_affected":"df58cf2ad82242fce89fa9b04f8328b46782dc39"}],"database_specific":{"cpe":["cpe:2.3:a:percona:xtrabackup:*:*:*:*:*:*:*:*","cpe:2.3:a:percona:xtrabackup:2.4.0:rc1:*:*:*:*:*:*","cpe:2.3:a:percona:xtrabackup:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:percona:xtrabackup:2.4.2:*:*:*:*:*:*:*","cpe:2.3:a:percona:xtrabackup:2.4.3:*:*:*:*:*:*:*","cpe:2.3:a:percona:xtrabackup:2.4.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.3.5"},{"introduced":"2.4.0-rc1"},{"last_affected":"2.4.0-rc1"},{"introduced":"2.4.1"},{"last_affected":"2.4.1"},{"introduced":"2.4.2"},{"last_affected":"2.4.2"},{"introduced":"2.4.3"},{"last_affected":"2.4.3"},{"introduced":"2.4.4"},{"last_affected":"2.4.4"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.4.0-rc1","2.4.1","2.4.2","2.4.3","2.4.4","percona-xtrabackup-2.4.4","percona-xtrabackup-2.3.5","mysql-5.6.11","clone-5.6.11-build","clone-5.6.9-rc-build","clone-5.6.7-rc-build","clone-5.6.6-m9-build","clone-5.6.3-m6-build","clone-5.6.3-m5-build","clone-5.4.0-build","mysqlsummit-0.2.1-build","mysqlsummit-0.2.1","mysqlsummit-0.2.0","mysqlsummit-0.2.0-build","clone-5.1.31-pv-0.2.0-build","mysql-5.1.4","clone-5.1.4-build","clone-5.1.0-build","mysql-4.0.4","mysql-4.0.2","mysql-3.23.36","mysql-3.23.33","mysql-3.23.32","mysql-3.23.31","mysql-3.23.30-gamma","mysql-3.23.28-gamma","mysql_4.0","mysql-3.23.22-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6225.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}