An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYPT_RIJNDAEL_256() function (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES) could help an attacker to create unknown havoc in the remote system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T15:18:49.391Z

Reserved: 2017-02-15T00:00:00

Link: CVE-2017-5999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-03-06T06:59:00.287

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-5999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.