CVE-2016-6313
published 2016-12-13CVE-2016-6313: The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it…
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
3.60%
88.2th percentile
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnupg1 | < gnupg1 1.4.21-1 (bookworm) | gnupg1 1.4.21-1 (bookworm) |
| debian | gnupg2 | < gnupg1 1.4.21-1 (bookworm) | gnupg1 1.4.21-1 (bookworm) |
| debian | libgcrypt20 | < gnupg1 1.4.21-1 (bookworm) | gnupg1 1.4.21-1 (bookworm) |
| gnupg | gnupg | <= 1.4.14 | — |
| gnupg | libgcrypt | <= 1.5.3 | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
| gnupg | libgcrypt | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44wq-cf78-w397: The mixing functions in the random number generator in Libgcrypt before 1
ghsa_unreviewed·2022-05-14
CVE-2016-6313 [MEDIUM] CWE-200 GHSA-44wq-cf78-w397: The mixing functions in the random number generator in Libgcrypt before 1
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
OSV
CVE-2016-6313: The mixing functions in the random number generator in Libgcrypt before 1
osv·2016-12-13·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313: The mixing functions in the random number generator in Libgcrypt before 1
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2016-08-18
CVE-2016-6313 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG incorrectly generated random numbers.
Felix Dörre and Vladimir Klebanov discovered that GnuPG incorrectly handled
mixing functions in the random number generator. An attacker able to obtain
4640 bits from the RNG can trivially predict the next 160 bits of output.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libgcrypt vulnerability
vendor_ubuntu·2016-08-18
CVE-2016-6313 Libgcrypt vulnerability
Title: Libgcrypt vulnerability
Summary: Libgcrypt incorrectly generated random numbers.
Felix Dörre and Vladimir Klebanov discovered that Libgcrypt incorrectly
handled mixing functions in the random number generator. An attacker able
to obtain 4640 bits from the RNG can trivially predict the next 160 bits of
output.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libgcrypt: PRNG output is predictable
vendor_redhat·2016-08-17·CVSS 5.3
CVE-2016-6313 [MEDIUM] libgcrypt: PRNG output is predictable
libgcrypt: PRNG output is predictable
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
A design flaw was found in the libgcrypt PRNG (Pseudo-Random Number Generator). An attacker able to obtain the first 580 bytes of the PRNG output could predict the following 20 bytes.
Package: libgcrypt (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-6313: gnupg1 - The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1...
vendor_debian·2016·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313: gnupg1 - The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1...
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
Scope: local
bookworm: resolved (fixed in 1.4.21-1)
bullseye: resolved (fixed in 1.4.21-1)
forky: resolved (fixed in 1.4.21-1)
sid: resolved (fixed in 1.4.21-1)
trixie: resolved (fixed in 1.4.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [epel-7]
bugzilla·2016-11-02·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [epel-7]
CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [fedora-all]
bugzilla·2016-11-02·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [fedora-all]
CVE-2016-6313 mingw-libgcrypt: libgcrypt: PRNG output is predictable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2016-6313 libgcrypt: PRNG output is predictable [fedora-all]
bugzilla·2016-08-18·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313 libgcrypt: PRNG output is predictable [fedora-all]
CVE-2016-6313 libgcrypt: PRNG output is predictable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2016-6313 libgcrypt: PRNG output is predictable
bugzilla·2016-08-11·CVSS 5.3
CVE-2016-6313 [MEDIUM] CVE-2016-6313 libgcrypt: PRNG output is predictable
CVE-2016-6313 libgcrypt: PRNG output is predictable
A design flaw was found in the libgcrypt PRNG (Pseudo-Random Number Generator). An attacker who can obtain the first 580 bytes of the PRNG output, can trivially predict the following 20 bytes.
Discussion:
Acknowledgements:
Name: Felix Dörre, Vladimir Klebanov
---
External Reference:
https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
---
Created libgcrypt tracking bugs for this issue:
Affects: fedora-all [bug 1368041]
---
Note that CVE-2016-6316 used in announcement is wrong, it should be CVE-2016-6313 as used in commit messages.
---
Upstream commit for libgcrypt 1.7:
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commitdiff;h=8dd45ad957b54b939c288a68720137386c7f6501
Upstream commit applied to li
CTF
crypto150-otp / README
ctf_writeups·2016·CVSS 5.3
[MEDIUM] crypto150-otp / README
# Crypto 150 — OTP
In this problem, we are given a remote web service that allows us to send arbitrary data, and have it be "encrypted" with a random string. However, before the encryption occurs, the flag for this problem will be appended to our input string. Then, the program will generate some number of bytes (up to 10000) of random data, and then XOR your string with it. Once the encryption has been completed, it sends the resulting string back to the sender. In addition to this, the program allows you to choose where the random data is being generated from. Among the available options are:
- /dev/urandom
- openssl
- gcrypt
- gnutls
Given a problem like this, our first instinct might be to send a really large request to drain the systems entropy, followed by a shorter guess. The ide
http://rhn.redhat.com/errata/RHSA-2016-2674.htmlhttp://www.debian.org/security/2016/dsa-3649http://www.debian.org/security/2016/dsa-3650http://www.securityfocus.com/bid/92527http://www.securitytracker.com/id/1036635http://www.ubuntu.com/usn/USN-3064-1http://www.ubuntu.com/usn/USN-3065-1https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWShttps://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.htmlhttps://security.gentoo.org/glsa/201610-04https://security.gentoo.org/glsa/201612-01http://rhn.redhat.com/errata/RHSA-2016-2674.htmlhttp://www.debian.org/security/2016/dsa-3649http://www.debian.org/security/2016/dsa-3650http://www.securityfocus.com/bid/92527http://www.securitytracker.com/id/1036635http://www.ubuntu.com/usn/USN-3064-1http://www.ubuntu.com/usn/USN-3065-1https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=blob_plain%3Bf=NEWShttps://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.htmlhttps://security.gentoo.org/glsa/201610-04https://security.gentoo.org/glsa/201612-01
2016-12-13
Published