Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7798

Опубликовано: 19 сент. 2016
Источник: redhat
CVSS3: 3.7
CVSS2: 4.3
EPSS Низкий

Описание

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

Меры по смягчению последствий

A possible workaround to this flaw is, when using aes-256-gcm mode, always set the key first and then the iv. For example when setting random keys and iv use the following code segment: key = cipher.random_key iv = cipher.random_iv

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5rh-ruby22-rubyWill not fix
CloudForms Management Engine 5ruby-200-rubyWill not fix
Red Hat Enterprise Linux 5rubyWill not fix
Red Hat Enterprise Linux 6rubyWill not fix
Red Hat Enterprise Linux 7rubyWill not fix
Red Hat Software Collectionsrh-ruby22-rubyWill not fix
Red Hat Software Collectionsrh-ruby23-rubyWill not fix
Red Hat Software Collectionsruby200-rubyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 69%
0.00597
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
nvd
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in G ...

CVSS3: 7.5
github
около 8 лет назад

OpenSSL gem for Ruby using inadequate encryption strength

EPSS

Процентиль: 69%
0.00597
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2