LWN.net Logo

beaker: information disclosure

Package(s):beaker CVE #(s):CVE-2012-3458
Created:September 10, 2012 Updated:September 12, 2012
Description: From the Debian advisory:

It was discovered that Beaker, a cache and session library for Python, when using the python-crypto backend, is vulnerable to information disclosure due to a cryptographic weakness related to the use of the AES cipher in ECB mode.

Systems that have the python-pycryptopp package should not be vulnerable, as this backend is preferred over python-crypto.

Alerts:
Debian DSA-2541-1 2012-09-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds