Perl Crypt::ECB Incorrect Block Encryption Weakness
BID:12012
Info
Perl Crypt::ECB Incorrect Block Encryption Weakness
| Bugtraq ID: | 12012 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 17 2004 12:00AM |
| Updated: | Dec 17 2004 12:00AM |
| Credit: | "Bennett R. Samowich" <[email protected]> disclosed this weakness. |
| Vulnerable: |
Christoph Appel Crypt::ECB 1.1 -2 Christoph Appel Crypt::ECB 1.1 |
| Not Vulnerable: | |
Discussion
Perl Crypt::ECB Incorrect Block Encryption Weakness
It is reported that Crypt::ECB is susceptible to a weakness when processing certain types of input. This is due to a failure of the module to properly validate user-supplied input data.
This weakness may potentially result in incorrect encryption and decryption of input data. If, for example, this Perl module were to be used in an application to store encrypted versions of passwords, this weakness may result in incorrect, and shorter passwords succeeding during authentication checks. This may aid attackers by simplifying passwords so brute force attacks are more likely to succeed. Other attacks may also be possible depending on the particular implementation of applications that utilize this Perl module.
It is reported that Crypt::ECB is susceptible to a weakness when processing certain types of input. This is due to a failure of the module to properly validate user-supplied input data.
This weakness may potentially result in incorrect encryption and decryption of input data. If, for example, this Perl module were to be used in an application to store encrypted versions of passwords, this weakness may result in incorrect, and shorter passwords succeeding during authentication checks. This may aid attackers by simplifying passwords so brute force attacks are more likely to succeed. Other attacks may also be possible depending on the particular implementation of applications that utilize this Perl module.
Exploit / POC
Perl Crypt::ECB Incorrect Block Encryption Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
Perl Crypt::ECB Incorrect Block Encryption Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Perl Crypt::ECB Incorrect Block Encryption Weakness
References:
References:
- Crypt::ECB Home Page (Christoph Appel)
- Bug in Crypt::ECB perl module ("Bennett R. Samowich"
)