VYPR
Medium severity5.3NVD Advisory· Published Dec 13, 2016· Updated May 6, 2026

CVE-2016-6313

CVE-2016-6313

Description

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.

Affected products

15
  • cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
    Range: <=1.4.14
  • Gnupg/Libgcrypt10 versions
    cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*range: <=1.5.3
    • cpe:2.3:a:gnupg:libgcrypt:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnupg:libgcrypt:1.7.2:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.