Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20637
HistoryJul 01, 2019 - 7:31 a.m.

Wrong And Predictable Encryption

2019-07-0107:31:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.007 Low

EPSS

Percentile

80.9%

github.com/golang/crypto is vulnerable to predictable encryption. In the keystream generation of more than 256 GiB in the amd64 implementation of golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa, it can first generate incorrect output and finally cycling back to the previously generated keystream.