CVE-2016-2183
Sweet32 attack (DES, 3DES)
Description
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Metrics
Affected operating systems
linux
redhat / enterprise_linux5.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
cisco
content_security_management_appliance
nodejs
node.js0.10.0 – 0.10.47
nodejs
node.js0.12.0 – 0.12.16
nodejs
node.js4.0.0 – 4.1.2
nodejs
node.js4.2.0 – 4.6.0
nodejs
node.js6.0.0 – 6.7.0
openssl
openssl
oracle
database
python
python2.7.0 – 2.7.13
python
python3.4.0 – 3.4.7
python
python3.5.0 – 3.5.3
redhat
jboss_enterprise_application_platform
redhat
jboss_enterprise_web_server
redhat
jboss_web_server
References & sources
- https://www.openssl.org/blog/blog/2016/08/24/sweet32/advisory
- https://bugs.python.org/issue27850report
- https://sweet32.info/web
- https://access.redhat.com/errata/RHSA-2017:3113vendor-advisory
- http://rhn.redhat.com/errata/RHSA-2017-0338.htmlvendor-advisory
- https://www.tenable.com/security/tns-2016-20
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_us
- https://security.gentoo.org/glsa/201612-16vendor-advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415
- https://access.redhat.com/errata/RHSA-2017:3240vendor-advisory
- https://www.tenable.com/security/tns-2016-16
- https://access.redhat.com/errata/RHSA-2017:2709vendor-advisory
- http://www.securityfocus.com/bid/92630vdb-entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499
- https://www.tenable.com/security/tns-2016-21
- https://kc.mcafee.com/corporate/index?page=content&id=SB10171
- https://access.redhat.com/errata/RHSA-2017:3239vendor-advisory