Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2012-08-26T21:00:00Z
Updated: 2024-08-06T19:26:08.199Z
Reserved: 2012-04-04T00:00:00Z
Link: CVE-2012-2146

No data.

Status : Modified
Published: 2012-08-26T21:55:01.840
Modified: 2024-11-21T01:38:35.803
Link: CVE-2012-2146
