Information disclosure in OpenSSL - CVE-2016-2183
Published: September 8, 2016 / Updated: March 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to decrypt transmitted data.
The vulnerability exists due to remote user's ability to control the network and capture long duration 3DES CBC mode encrypted session during which he can see a part of the text. In case of repeated sending the attacker can read the part and reconstruct the whole text.
Successful exploitation of this vulnerability may allow a remote attacker to decode transmitted data. This vulnerability is known as SWEET32.
Affected software
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
IBM i
Red Hat Enterprise Linux for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux
Ubuntu
Slackware Linux
Opensuse
SkyBridge MB-A200
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
IBM Integrated Management Module
PowerFlex Manager
XtremIO X2
DevOps
Dell EMC PowerMax Embedded NAS (eNAS)
Network Advisor
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
JBoss Enterprise Web Server
openwsman (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl
openssl-solibs
dev-libs/openssl
Red Hat OpenShift Container Platform
Puppet Enterprise
IBM Algo One Core
Algo One Algo Risk Application
IBM Cloud Pak for Data Scheduling
IBM Rational Build Forge
NetWorker
EMC Data Protection Advisor
Security Director Insights
Oracle Java SE
JBoss Enterprise Application Platform
IBM InfoSphere Information Server
Juniper Junos Space
Puppet Agent
EMC Integrated Data Protection Appliance
IBM Storwize V3700
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V7000
IBM FlashSystem V9000
Content Manager Enterprise Edition
How to mitigate CVE-2016-2183
IBM Cloud Pak for Data Scheduling - update to 5.2.0
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Juniper Junos Space - update to 24.1R2
IBM Integrated Management Module - update to YUOOH4B - 1.53
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
Puppet Agent - update to 1.7.1
EMC Integrated Data Protection Appliance - update to 2.7.6
PowerFlex Manager - update to 3.5.0-5507
XtremIO X2 - update to 6.4.2-13
DevOps - update to 7.0.0.2
FOS Firmware - addressed in versions 7.4.2a, 8.01c
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Rational Build Forge - update to 8.0.0.27
Dell EMC PowerMax Embedded NAS (eNAS) - update to 8.1.15.24
Content Manager Enterprise Edition - update to 8.5.0.6.2
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
EMC Data Protection Advisor - update to 19.10 PB22
Security Director Insights - update to 23.1R1
Puppet Enterprise - update to 2016.4.0
External References
Related Security Bulletins
- Information disclosure in OpenSSL
- SUSE Linux update for java-1_6_0-ibm
- Multiple vulnerabilities in Oracle products
- Gentoo update for IcedTea
- Ubuntu update for NSS
- Ubuntu update for NSS
- Ubuntu update for OpenJDK 6
- Ubuntu update for OpenJDK 7
- Ubuntu update for OpenJDK 8
- Amazon Linux AMI update for java-1.7.0-openjdk
- Amazon Linux AMI update for java-1.8.0-openjdk
- openSUSE update for openssl-steam
- SUSE Linux update for java-1
- OpenSUSE Linux update for java-1
- Multiple vulnerabilities in IBM Algo One Core and Algo Risk Application
- Red Hat update for python
- Red Hat update for Red Hat JBoss Enterprise Application Platform 6.4.18
- Red Hat update for Red Hat JBoss Web Server
- Red Hat update for java-1.8.0-ibm
- Red Hat update for java-1.7.0-openjdk
- Red Hat update for java-1.8.0-openjdk
- Red Hat update for OpenShift Container Platform 4.1.18
- Red Hat update for OpenShift Container Platform 3.11
- Information disclosure in openwsman (Alpine package)
- Slackware Linux update for python
- Multiple vulnerabilities in Dell EMC PowerMax Embedded NAS (eNAS)
- Multiple vulnerabilities in Dell PowerFlex Manager
- Information disclosure in IBM InfoSphere Information server
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in Seiko Solutions SkyBridge MB-A100/A110/A200/A130 and SkySpider MB-R210
- Multiple vulnerabilities in Multiple N series Products
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Multiple vulnerabilities in IBM Integrated Management Module (IMM) for System x & BladeCenter
- Multiple vulnerabilities in Juniper Networks Security Director Insights
- Multiple vulnerabilities in IBM Content Manager Enterprise Edition
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in Data Protection Advisor
- Multiple vulnerabilities in IBM DevOps Release
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Dell XtremIO X2
- Gentoo update for OpenSSL
- Slackware Linux update for openssl
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 update for openssl
- Multiple vulnerabilities in IBM CloudPak for Data Scheduling Service
- Puppet Enterprise and Puppet Agent update for OpenSSL
- Dell EMC PowerMax Embedded NAS update for third-party components