CVE-2016-6313

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
13/12/2016
Last modified:
12/04/2025

Description

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* 1.5.3 (including)
cpe:2.3:a:gnupg:libgcrypt:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:gnupg:libgcrypt:1.7.2:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 1.4.14 (including)