Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882589
Category:CentOS Local Security Checks
Title:CentOS Update for libgcrypt CESA-2016:2674 centos6
Summary:Check the version of libgcrypt
Description:Summary:
Check the version of libgcrypt

Vulnerability Insight:
The libgcrypt library provides
general-purpose implementations of various cryptographic algorithms.

Security Fix(es):

* A design flaw was found in the libgcrypt PRNG (Pseudo-Random Number
Generator). An attacker able to obtain the first 580 bytes of the PRNG
output could predict the following 20 bytes. (CVE-2016-6313)

Red Hat would like to thank Felix Dorre and Vladimir Klebanov for reporting
this issue.

Affected Software/OS:
libgcrypt on CentOS 6

Solution:
Please Install the Updated Packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6313
BugTraq ID: 92527
http://www.securityfocus.com/bid/92527
Debian Security Information: DSA-3649 (Google Search)
http://www.debian.org/security/2016/dsa-3649
Debian Security Information: DSA-3650 (Google Search)
http://www.debian.org/security/2016/dsa-3650
https://security.gentoo.org/glsa/201610-04
https://security.gentoo.org/glsa/201612-01
https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
RedHat Security Advisories: RHSA-2016:2674
http://rhn.redhat.com/errata/RHSA-2016-2674.html
http://www.securitytracker.com/id/1036635
http://www.ubuntu.com/usn/USN-3064-1
http://www.ubuntu.com/usn/USN-3065-1
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.