Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Boramao

#37160of 53,625
7.5Total CVSS
Vulnerabilities · 1
PT-2017-9351
7.5
2016-10-13
Openssl · Openssl · CVE-2016-7798
**Name of the Vulnerable Software and Affected Versions** openssl gem for Ruby (affected versions not specified) **Description** The issue arises when the initialization vector (IV) is set before the key in GCM Mode (aes-*-gcm), allowing context-dependent attackers to bypass the encryption protection mechanism. This makes it easier for attackers to exploit the situation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.