CVE-2016-7798
30.01.2017, 22:59
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ruby-lang | openssl | 𝑥 < 2.0.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ruby-attr-encrypted |
| ||||||||||||||||||||||||||||||||||||||
| ruby-encryptor |
| ||||||||||||||||||||||||||||||||||||||
| ruby1.8 |
| ||||||||||||||||||||||||||||||||||||||
| ruby1.9.1 |
| ||||||||||||||||||||||||||||||||||||||
| ruby2.0 |
| ||||||||||||||||||||||||||||||||||||||
| ruby2.1 |
| ||||||||||||||||||||||||||||||||||||||
| ruby2.3 |
|
Common Weakness Enumeration
References