Inadequate Cryptographic Key Size and Insecure Cryptographic Mode. File Name :- curl_ntlm_core.c

Disclosed: 2021-03-08 08:24:10 By sanchitcfc To curl
High
Vulnerability Details
The application is generating cryptographic keys or key pairs using a short and inadequate length. This application is using the ECB (Electronic Codebook) mode of operation to perform encryption, which is considered semantically insecure. Vulnerable File name :- curl_ntlm_core.c Vulnerable line no. 274 :- err = CCCrypt(kCCEncrypt, kCCAlgorithmDES, kCCOptionECBMode, key, ## Impact If a message with identical blocks is encrypted, an attacker get a certain advantage to have information on plaintext, by only observing CipherText.
Actions
View on HackerOne
Report Stats
  • Report ID: 1113663
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 1
Share this report