CVE-2016-7798

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruby-lang:openssl:*:*:*:*:*:ruby:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-01-30 22:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-7798

Mitre link : CVE-2016-7798

CVE.ORG link : CVE-2016-7798


JSON object : View

Products Affected

ruby-lang

  • openssl

debian

  • debian_linux
CWE
CWE-326

Inadequate Encryption Strength