ISOMAN

CVE

CVE-2016-6313

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.

Severity
MEDIUM
CVSS
5.3
Published
Modified

Linked Releases

References

  1. http://rhn.redhat.com/errata/RHSA-2016-2674.html
  2. http://www.debian.org/security/2016/dsa-3649
  3. http://www.debian.org/security/2016/dsa-3650
  4. http://www.securityfocus.com/bid/92527
  5. http://www.securitytracker.com/id/1036635
  6. http://www.ubuntu.com/usn/USN-3064-1
  7. http://www.ubuntu.com/usn/USN-3065-1
  8. https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWS
  9. https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
  10. https://security.gentoo.org/glsa/201610-04
  11. https://security.gentoo.org/glsa/201612-01
  12. http://rhn.redhat.com/errata/RHSA-2016-2674.html
  13. http://www.debian.org/security/2016/dsa-3649
  14. http://www.debian.org/security/2016/dsa-3650
  15. http://www.securityfocus.com/bid/92527
  16. http://www.securitytracker.com/id/1036635
  17. http://www.ubuntu.com/usn/USN-3064-1
  18. http://www.ubuntu.com/usn/USN-3065-1
  19. https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWS
  20. https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html