CVE
- Id
- 102819
- CVE No.
- CVE-2017-5999
- Status
- Candidate
- Description
- An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES) could help an attacker to create unknown havoc in the remote system.
- Phase
- Assigned (20170215)
- Votes
- None (candidate not yet proposed)
- Comments