Learn about Centmin Mod LEMP Stack today
Register Now

OpenSSL The SWEET32 Issue, CVE-2016-2183

Discussion in 'CentOS, Redhat & Oracle Linux News' started by buik, Aug 25, 2016.

Tags:
  1. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    11:26 PM
    Today, Karthik Bhargavan and Gaetan Leurent from Inria
    have unveiled a new attack on Triple-DES, SWEET32,
    Birthday attacks on 64-bit block ciphers in TLS.

    It has been assigned CVE-2016-2183.

    BTW. The only positive news in this article:
    For the 1.1.0 release, which we expect to release tomorrow.

     
  2. eva2000

    eva2000 Administrator Staff Member

    59,722
    12,541
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,185
    Local Time:
    7:26 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Thanks for heads up @bassie (y)

    luckily Centmin Mod Nginx default ssl ciphers these days have it disabled out of the box for most