Libgcrypt weak encryption in Oracle products - CVE-2016-6313
Published: August 18, 2016 / Updated: January 11, 2017
Vulnerability details
The vulnerability allows a local user to decrypt data.
The vulnerability exists in the Libgcrypt library due to weak implementation of random number generator. A local user, who can obtain 4640 bits from random generator, can predict the next 160 bits of output.
Successful exploitation of this vulnerability may result in generation of weak encryption keys and may lead to sensitive information disclosure.
Affected software
Oracle VM Server for x86
Oracle Linux
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Ubuntu
Slackware Linux
Fedora
libgcrypt (Alpine package)
gnupg
libgcrypt
IBM Tivoli Storage Manager
Integrated Management Module II (IMM2)
How to mitigate CVE-2016-6313
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
gnupg - addressed in versions 1.4.21-1.fc23, 1.4.21-1.fc24, 1.4.21-1.fc25
libgcrypt - addressed in versions 1.6.6-1.fc23, 1.6.6-1.fc25
External References
Related Security Bulletins
- Predictable random number generator output in Libgcrypt
- Predictable Libgcrypt random number generator output in GnuPG
- Debian update for libgcrypt20
- Debian update for gnupg
- Ubuntu update for Libgcrypt
- Ubuntu update for GnuPG
- Arch Linux update for lib32-libgcrypt
- Arch Linux update for libgcrypt
- Slackware Linux update for libgcrypt
- Slackware Linux update for gnupg
- Amazon Linux AMI update for libgcrypt, gnupg
- Gentoo update for GnuPG
- Red Hat update for libgcrypt
- Libgcrypt weak encryption in libgcrypt (Alpine package)
- Libgcrypt weak encryption in IBM Integrated Management Module II (IMM2)
- Fedora 23 update for libgcrypt
- Fedora 25 update for libgcrypt
- Fedora 25 update for gnupg
- Fedora 24 update for gnupg
- Fedora 23 update for gnupg