Vulnerability CVE-2008-2780


Published: 2008-06-19   Modified: 2012-02-12

Description:
The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, which allows attackers to distinguish between encrypted data and random padding at the end of the encrypted file.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Albinoloverats -> Anubis plugin 

 References:
https://albinoloverats.net/index.php?option=com_content&task=view&id=60&Itemid=2
http://xforce.iss.net/xforce/xfdb/42652
http://www.vupen.com/english/advisories/2008/1663/references
http://secunia.com/advisories/30388

Copyright 2020, cxsecurity.com

 

Back to Top