Rapid7

vulnerability

Ubuntu: USN-3365-1 (CVE-2016-7798): Ruby vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jan 30, 2017
Added
Jul 26, 2017
Modified
Mar 27, 2026

Description

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

Solutions

ubuntu-upgrade-libruby1-9-1ubuntu-upgrade-libruby2-0ubuntu-upgrade-libruby2-3ubuntu-upgrade-ruby1-9-1ubuntu-upgrade-ruby2-0ubuntu-upgrade-ruby2-3
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.