CVE-2016-7798
published 2017-01-30CVE-2016-7798: The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.17%
86.7th percentile
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-attr-encrypted | < ruby-attr-encrypted 3.0.1-2 (bookworm) | ruby-attr-encrypted 3.0.1-2 (bookworm) |
| debian | ruby-encryptor | < ruby-attr-encrypted 3.0.1-2 (bookworm) | ruby-attr-encrypted 3.0.1-2 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_openssl_1.1.1k-5_on_cbl_mariner_1.0 | — | — |
| openssl | openssl | >= 0 < 2.0.0 | 2.0.0 |
| ruby-lang | openssl | < 2.0.0 | 2.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenSSL gem for Ruby using inadequate encryption strength
osv·2017-10-24
CVE-2016-7798 [HIGH] OpenSSL gem for Ruby using inadequate encryption strength
OpenSSL gem for Ruby using inadequate encryption strength
The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
GHSA
OpenSSL gem for Ruby using inadequate encryption strength
ghsa·2017-10-24
CVE-2016-7798 [HIGH] CWE-326 OpenSSL gem for Ruby using inadequate encryption strength
OpenSSL gem for Ruby using inadequate encryption strength
The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
OSV
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
osv·2017-07-25·CVSS 7.3
CVE-2009-5147 [HIGH] ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
It was discovered that Ruby DL::dlopen incorrectly handled opening
libraries. An attacker could possibly use this issue to open libraries with
tainted names. This issue only applied to Ubuntu 14.04 LTS. (CVE-2009-5147)
Tony Arcieri, Jeffrey Walton, and Steffan Ullrich discovered that the Ruby
OpenSSL extension incorrectly handled hostname wildcard matching. This
issue only applied to Ubuntu 14.04 LTS. (CVE-2015-1855)
Christian Hofstaedtler discovered that Ruby Fiddle::Handle incorrectly
handled certain crafted strings. An attacker could use this issue to cause
a denial of service, or possibly execute arbitrary code. This issue only
applied to Ubuntu 14.04 LTS. (CVE-2015-7551)
It was discovered that Ruby Net::SMTP incorrectly handled CRLF sequ
OSV
CVE-2016-7798: The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for
osv·2017-01-30·CVSS 7.5
CVE-2016-7798 [HIGH] CVE-2016-7798: The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2017-07-25·CVSS 7.3
CVE-2009-5147 [HIGH] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby DL::dlopen incorrectly handled opening
libraries. An attacker could possibly use this issue to open libraries with
tainted names. This issue only applied to Ubuntu 14.04 LTS. (CVE-2009-5147)
Tony Arcieri, Jeffrey Walton, and Steffan Ullrich discovered that the Ruby
OpenSSL extension incorrectly handled hostname wildcard matching. This
issue only applied to Ubuntu 14.04 LTS. (CVE-2015-1855)
Christian Hofstaedtler discovered that Ruby Fiddle::Handle incorrectly
handled certain crafted strings. An attacker could use this issue to cause
a denial of service, or possibly execute arbitrary code. This issue only
applied to Ubuntu 14.04 LTS. (CVE-2015-7551)
It was discovered that Ruby N
Microsoft
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key which makes it easier for context-dependent attackers to bypass the encrypti
vendor_msrc·2017-01-10·CVSS 7.5
CVE-2016-7798 [HIGH] CWE-326 The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key which makes it easier for context-dependent attackers to bypass the encrypti
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identi
Red Hat
ruby: IV Reuse in GCM Mode
vendor_redhat·2016-09-19·CVSS 7.5
CVE-2016-7798 [HIGH] ruby: IV Reuse in GCM Mode
ruby: IV Reuse in GCM Mode
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
Mitigation: A possible workaround to this flaw is, when using aes-256-gcm mode, always set the key first and then the iv. For example when setting random keys and iv use the following code segment:
key = cipher.random_key
iv = cipher.random_iv
Package: rh-ruby22-ruby (CloudForms Management Engine 5) - Will not fix
Package: ruby-200-ruby (CloudForms Management Engine 5) - Will not fix
Package: ruby (Red Hat Enterprise Linux 5) - Will not fix
Package: ruby (Red Hat Enterprise Linux 6) - Will not fix
Package: ruby (Red Hat Enterprise Lin
Debian
CVE-2016-7798: ruby-attr-encrypted - The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (a...
vendor_debian·2016·CVSS 7.5
CVE-2016-7798 [HIGH] CVE-2016-7798: ruby-attr-encrypted - The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (a...
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
Scope: local
bookworm: resolved (fixed in 3.0.1-2)
bullseye: resolved (fixed in 3.0.1-2)
sid: resolved (fixed in 3.0.1-2)
trixie: resolved (fixed in 3.0.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7798 ruby: IV Reuse in GCM Mode
bugzilla·2016-10-04·CVSS 7.5
CVE-2016-7798 [HIGH] CVE-2016-7798 ruby: IV Reuse in GCM Mode
CVE-2016-7798 ruby: IV Reuse in GCM Mode
An IV reuse bug was discovered in Ruby's OpenSSL library when using
aes-gcm. When encrypting data with aes-*-gcm, if the IV is set before
setting the key, the cipher will default to using a static IV. This creates
a static nonce and since aes-gcm is a stream cipher, this can lead to known
cryptographic issues.
References:
http://seclists.org/oss-sec/2016/q3/562
Upstream bug:
https://github.com/ruby/openssl/issues/49
Upstream patch:
https://github.com/ruby/openssl/commit/8108e0a6db133f3375608303fdd2083eb5115062
Discussion:
Created ruby tracking bugs for this issue:
Affects: fedora-all [bug 1381527]
---
Analysis:
As explained in https://github.com/ruby/openssl/issues/49#issuecomment-248171371
Calling cipher.key after calling cipher.iv zer
Bugzilla
CVE-2016-7798 ruby: IV Reuse in GCM Mode [fedora-all]
bugzilla·2016-10-04·CVSS 7.5
CVE-2016-7798 [HIGH] CVE-2016-7798 ruby: IV Reuse in GCM Mode [fedora-all]
CVE-2016-7798 ruby: IV Reuse in GCM Mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one t
http://www.openwall.com/lists/oss-security/2016/09/19/9http://www.openwall.com/lists/oss-security/2016/09/30/6http://www.openwall.com/lists/oss-security/2016/10/01/2http://www.securityfocus.com/bid/93031https://github.com/ruby/openssl/commit/8108e0a6db133f3375608303fdd2083eb5115062https://github.com/ruby/openssl/issues/49https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlhttps://www.debian.org/security/2017/dsa-3966http://www.openwall.com/lists/oss-security/2016/09/19/9http://www.openwall.com/lists/oss-security/2016/09/30/6http://www.openwall.com/lists/oss-security/2016/10/01/2http://www.securityfocus.com/bid/93031https://github.com/ruby/openssl/commit/8108e0a6db133f3375608303fdd2083eb5115062https://github.com/ruby/openssl/issues/49https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlhttps://www.debian.org/security/2017/dsa-3966
2017-01-30
Published