VDB
ALPINE-CVE-2016-2183
ALPINE-CVE-2016-2183
PUBLISHED
CVSS 7.5 HIGH
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.4 | openssl | 1.0.2, 1.0.2, 1.0.2 |
| Alpine:v3.2 | openssl | *, 1.0.2, 1.0.2 |
| Alpine:v3.6 | openssl | 0, 0.9.8i-r0, 0.9.8j-r0 |
| Alpine:v3.7 | openssl | 1.0.1e-r4, 1.0.2, 1.0.2 |
| Alpine:v3.3 | openssl | 1.0.1, 1.0.2, 1.0.2 |
| Alpine:v3.8 | openssl | 0, 1.0.2, 1.0.2 |
| Alpine:v3.5 | openssl | 0.9.8i-r0, 1.0.2, 1.0.2 |
Exploit Intelligence
Timeline
- Sep 1, 2016 CVE Published
- Apr 11, 2025 PoC Published
- Nov 19, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch