Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7798

Опубликовано: 30 янв. 2017
Источник: debian
EPSS Низкий

Описание

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby2.3fixed2.3.3-1+deb9u1package
ruby2.1removedpackage
ruby-attr-encryptedfixed3.0.1-2package
ruby-encryptorfixed3.0.0-1package

Примечания

  • https://github.com/ruby/openssl/issues/49

  • https://github.com/ruby/openssl/commit/8108e0a6db133f3375608303fdd2083eb5115062

  • https://github.com/attr-encrypted/attr_encrypted/issues/203

  • https://github.com/attr-encrypted/encryptor/pull/22

EPSS

Процентиль: 42%
0.00195
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 3.7
redhat
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
nvd
больше 8 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.5
github
больше 7 лет назад

OpenSSL gem for Ruby using inadequate encryption strength

EPSS

Процентиль: 42%
0.00195
Низкий