CVE-2016-2183
Sweet32 attack (DES, 3DES)
Beschreibung
Die DES- und Triple-DES-Chiffren, wie sie im TLS-, SSH- und IPSec-Protokoll sowie anderen Protokollen und Produkten verwendet werden, haben eine Geburtstagsgrenze von etwa vier Milliarden Blöcken. Dies erleichtert es Fernangreifern, Klartextdaten über einen Geburtstag-Angriff gegen eine lange verschlüsselte Sitzung zu erhalten, wie an einem HTTPS-Sitzungsbeispiel mit Triple DES im CBC-Modus gezeigt wurde, bekannt als "Sweet32"-Angriff.
Metriken
Betroffene Betriebssysteme
linux
redhat / enterprise_linux5.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
cisco
content_security_management_appliance
nodejs
node.js0.10.0 – 0.10.47
nodejs
node.js0.12.0 – 0.12.16
nodejs
node.js4.0.0 – 4.1.2
nodejs
node.js4.2.0 – 4.6.0
nodejs
node.js6.0.0 – 6.7.0
openssl
openssl
oracle
database
python
python2.7.0 – 2.7.13
python
python3.4.0 – 3.4.7
python
python3.5.0 – 3.5.3
redhat
jboss_enterprise_application_platform
redhat
jboss_enterprise_web_server
redhat
jboss_web_server
Quellen & Referenzen
- https://www.openssl.org/blog/blog/2016/08/24/sweet32/advisory
- https://bugs.python.org/issue27850report
- https://sweet32.info/web
- https://access.redhat.com/errata/RHSA-2017:3113vendor-advisory
- http://rhn.redhat.com/errata/RHSA-2017-0338.htmlvendor-advisory
- https://www.tenable.com/security/tns-2016-20
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_us
- https://security.gentoo.org/glsa/201612-16vendor-advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415
- https://access.redhat.com/errata/RHSA-2017:3240vendor-advisory
- https://www.tenable.com/security/tns-2016-16
- https://access.redhat.com/errata/RHSA-2017:2709vendor-advisory
- http://www.securityfocus.com/bid/92630vdb-entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499
- https://www.tenable.com/security/tns-2016-21
- https://kc.mcafee.com/corporate/index?page=content&id=SB10171
- https://access.redhat.com/errata/RHSA-2017:3239vendor-advisory