Debian Security Advisory

DLA-600-1 libgcrypt11 -- LTS security update

Date Reported:
23 Aug 2016
Affected Packages:
libgcrypt11
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-6313.
More information:

The crypto library libgcrypt11 has a weakness in the random number generator.

  • CVE-2016-6313

    Felix Dörre and Vladimir Klebanov from the Karlsruhe Institute of Technology found a bug in the mixing functions of Libgcrypt's random number generator. An attacker who obtains 4640 bits from the RNG can trivially predict the next 160 bits of output.

A first analysis on the impact of this bug in GnuPG shows that existing RSA keys are not weakened. For DSA and Elgamal keys it is also unlikely that the private key can be predicted from other public information.

For Debian 7 Wheezy, these problems have been fixed in version 1.5.0-5+deb7u5.

We recommend that you upgrade your libgcrypt11 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS