UBUNTU-CVE-2016-2183
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-2183
UBUNTU-CVE-2016-2183
Summary:
Details: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
References: https://ubuntu.com/security/CVE-2016-2183, https://sweet32.info/, https://access.redhat.com/articles/2548661, https://access.redhat.com/security/cve/cve-2016-2183, https://blog.cryptographyengineering.com/2016/08/24/attack-of-week-64-bit-ciphers-in-tls/, https://community.qualys.com/thread/16555, https://github.com/ssllabs/ssllabs-scan/issues/387#issuecomment-242514633, https://nakedsecurity.sophos.com/2016/08/25/anatomy-of-a-cryptographic-collision-the-sweet32-attack/, https://quickview.cloudapps.cisco.com/quickview/bug/CSCvb05575, https://security-tracker.debian.org/tracker/CVE-2016-2183, https://twitter.com/symantec/status/768786631159603200, https://www.ietf.org/mail-archive/web/tls/current/msg04560.html, https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2016/august/new-practical-attacks-on-64-bit-block-ciphers-3des-blowfish/, https://www.openssl.org/blog/blog/2016/08/24/sweet32/, https://www.sigsac.org/ccs/CCS2016/accepted-papers/, https://www.suse.com/security/cve/CVE-2016-2183.html, https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue, https://ubuntu.com/security/notices/USN-3087-1, http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/5d2bb853ae31, https://ubuntu.com/security/notices/USN-3179-1, https://ubuntu.com/security/notices/USN-3194-1, https://ubuntu.com/security/notices/USN-3198-1, https://ubuntu.com/security/notices/USN-3270-1, https://ubuntu.com/security/notices/USN-3372-1, https://www.cve.org/CVERecord?id=CVE-2016-2183
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
