Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Boramao

#35216de 53,633
7.5CVSS total
Vulnerabilidades · 1
PT-2017-9351
7.5
2016-10-13
Openssl · Openssl · CVE-2016-7798
**Name of the Vulnerable Software and Affected Versions** openssl gem for Ruby (affected versions not specified) **Description** The issue arises when the initialization vector (IV) is set before the key in GCM Mode (aes-*-gcm), allowing context-dependent attackers to bypass the encryption protection mechanism. This makes it easier for attackers to exploit the situation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.