High severity7.5NVD Advisory· Published Apr 19, 2017· Updated May 13, 2026
CVE-2013-7463
CVE-2013-7463
Description
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aescryptRubyGems | <= 1.0.0 | — |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/Gurpartap/aescrypt/issues/4nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-4c4w-3q45-hp9jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-7463ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/aescrypt/CVE-2013-7463.ymlghsaWEB
- web.archive.org/web/20200227173428/http://www.securityfocus.com/bid/98035ghsaWEB
- www.securityfocus.com/bid/98035nvd
News mentions
0No linked articles in our index yet.