CVE-2014-2319

The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:powerarchiver:powerarchiver:*:*:*:*:*:*:*:*
cpe:2.3:a:powerarchiver:powerarchiver:14.00:*:*:*:*:*:*:*
cpe:2.3:a:powerarchiver:powerarchiver:14.01:*:*:*:*:*:*:*
cpe:2.3:a:powerarchiver:powerarchiver:14.02:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://int21.de/cve/CVE-2014-2319-powerarchiver.html - () http://int21.de/cve/CVE-2014-2319-powerarchiver.html -
References () http://www.powerarchiver.com/2014/03/12/powerarchiver-2013-14-02-05-released/ - Vendor Advisory () http://www.powerarchiver.com/2014/03/12/powerarchiver-2013-14-02-05-released/ - Vendor Advisory

Information

Published : 2014-03-14 10:55

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2319

Mitre link : CVE-2014-2319

CVE.ORG link : CVE-2014-2319


JSON object : View

Products Affected

powerarchiver

  • powerarchiver
CWE
CWE-310

Cryptographic Issues