Back to search
CVE-2016-6329
Published: Jan 31, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://sweet32.info/
x_refsource_MISC
1036695
vdb-entry
x_refsource_SECTRACK
http://www-01.ibm.com/support/docview.wss?uid=swg21995039
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21991482
x_refsource_CONFIRM
GLSA-201611-02
vendor-advisory
x_refsource_GENTOO
https://community.openvpn.net/openvpn/wiki/SWEET32
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697
x_refsource_CONFIRM
92631
vdb-entry
x_refsource_BID
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now