CVE-2016-7798
30.01.2017, 22:59
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.Enginsight
Vendor | Product | Version |
---|---|---|
ruby-lang | openssl | 𝑥 < 2.0.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ruby-attr-encrypted |
| ||||||||||||||||||||||||||||||||||||||
ruby-encryptor |
| ||||||||||||||||||||||||||||||||||||||
ruby1.8 |
| ||||||||||||||||||||||||||||||||||||||
ruby1.9.1 |
| ||||||||||||||||||||||||||||||||||||||
ruby2.0 |
| ||||||||||||||||||||||||||||||||||||||
ruby2.1 |
| ||||||||||||||||||||||||||||||||||||||
ruby2.3 |
|
Common Weakness Enumeration
References