Description
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2009-1008 Vulnerability (CVE-2009-1008)
Joomla! Core 4.x.x Multiple Vulnerabilities (4.0.0 - 4.2.6)
Sqlite Improper Handling of Exceptional Conditions Vulnerability (CVE-2019-19924)
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7324)