CVE-2016-2183

EUVD-2016-3268
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_web_server
1.0.0
redhatjboss_enterprise_web_server
2.0.0
redhatjboss_web_server
3.0
redhatenterprise_linux
5.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
pythonpython
2.7.0 ≤
𝑥
< 2.7.13
pythonpython
3.4.0 ≤
𝑥
< 3.4.7
pythonpython
3.5.0 ≤
𝑥
< 3.5.3
ciscocontent_security_management_appliance
9.6.6-068
ciscocontent_security_management_appliance
9.7.0-006
opensslopenssl
1.0.1a:a
opensslopenssl
1.0.1b:b
opensslopenssl
1.0.1c:c
opensslopenssl
1.0.1d:d
opensslopenssl
1.0.1e:e
opensslopenssl
1.0.1f:f
opensslopenssl
1.0.1g:g
opensslopenssl
1.0.1h:h
opensslopenssl
1.0.1i:i
opensslopenssl
1.0.1j:j
opensslopenssl
1.0.1k:k
opensslopenssl
1.0.1l:l
opensslopenssl
1.0.1m:m
opensslopenssl
1.0.1n:n
opensslopenssl
1.0.1o:o
opensslopenssl
1.0.1p:p
opensslopenssl
1.0.1q:q
opensslopenssl
1.0.1r:r
opensslopenssl
1.0.1t:t
opensslopenssl
1.0.2a:a
opensslopenssl
1.0.2b:b
opensslopenssl
1.0.2c:c
opensslopenssl
1.0.2d:d
opensslopenssl
1.0.2e:e
opensslopenssl
1.0.2f:f
opensslopenssl
1.0.2h:h
oracledatabase
11.2.0.4
oracledatabase
12.1.0.2
nodejsnode.js
0.10.0 ≤
𝑥
< 0.10.47
nodejsnode.js
0.12.0 ≤
𝑥
< 0.12.16
nodejsnode.js
4.0.0 ≤
𝑥
< 4.1.2
nodejsnode.js
4.2.0 ≤
𝑥
< 4.6.0
nodejsnode.js
6.0.0 ≤
𝑥
< 6.7.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls26
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
not-affected
trusty
not-affected
xenial
dne
yakkety
dne
zesty
dne
gnutls28
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
not-affected
trusty
dne
xenial
not-affected
yakkety
not-affected
zesty
not-affected
nss
artful
Fixed 2:3.28.4-0ubuntu1
released
bionic
Fixed 2:3.28.4-0ubuntu1
released
cosmic
Fixed 2:3.28.4-0ubuntu1
released
disco
Fixed 2:3.28.4-0ubuntu1
released
precise
ignored
trusty
Fixed 2:3.28.4-0ubuntu0.14.04.1
released
xenial
Fixed 2:3.28.4-0ubuntu0.16.04.1
released
yakkety
Fixed 2:3.28.4-0ubuntu0.16.10.1
released
zesty
Fixed 2:3.28.4-0ubuntu0.17.04.1
released
openjdk-6
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
Fixed 6b41-1.13.13-0ubuntu0.12.04.1
released
trusty
Fixed 6b41-1.13.13-0ubuntu0.14.04.1
released
xenial
dne
yakkety
dne
zesty
dne
openjdk-7
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
Fixed 7u121-2.6.8-1ubuntu0.12.04.3
released
trusty
Fixed 7u121-2.6.8-1ubuntu0.14.04.3
released
xenial
dne
yakkety
dne
zesty
dne
openjdk-8
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
precise
dne
trusty
dne
xenial
Fixed 8u121-b13-0ubuntu1.16.04.2
released
yakkety
Fixed 8u121-b13-0ubuntu1.16.10.2
released
zesty
not-affected
openssl
artful
Fixed 1.0.2g-1ubuntu9
released
bionic
Fixed 1.0.2g-1ubuntu9
released
cosmic
Fixed 1.0.2g-1ubuntu9
released
disco
Fixed 1.0.2g-1ubuntu9
released
precise
Fixed 1.0.1-4ubuntu5.37
released
trusty
Fixed 1.0.1f-1ubuntu2.20
released
xenial
Fixed 1.0.2g-1ubuntu4.4
released
yakkety
Fixed 1.0.2g-1ubuntu9
released
zesty
Fixed 1.0.2g-1ubuntu9
released
openssl098
artful
dne
bionic
dne
cosmic
dne
disco
dne
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
References