{"id":"USN-3065-1","summary":"libgcrypt11, libgcrypt20 vulnerability","details":"Felix Dörre and Vladimir Klebanov discovered that Libgcrypt incorrectly\nhandled mixing functions in the random number generator. An attacker able\nto obtain 4640 bits from the RNG can trivially predict the next 160 bits of\noutput.\n","modified":"2026-04-22T09:26:38.217283Z","published":"2016-08-18T18:32:29Z","related":["UBUNTU-CVE-2016-6313"],"upstream":["CVE-2016-6313","UBUNTU-CVE-2016-6313"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3065-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-6313"}],"affected":[{"package":{"name":"libgcrypt11","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/libgcrypt11@1.5.3-2ubuntu4.4?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-2ubuntu4.4"}]}],"versions":["1.5.0-3ubuntu3","1.5.3-2ubuntu1","1.5.3-2ubuntu4","1.5.3-2ubuntu4.1","1.5.3-2ubuntu4.2","1.5.3-2ubuntu4.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libgcrypt11","binary_version":"1.5.3-2ubuntu4.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3065-1.json","cves_map":{"cves":[{"id":"CVE-2016-6313","severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}]}],"ecosystem":"Ubuntu:14.04:LTS"}}},{"package":{"name":"libgcrypt20","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libgcrypt20@1.6.5-2ubuntu0.2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.5-2ubuntu0.2"}]}],"versions":["1.6.3-2ubuntu1","1.6.4-3","1.6.4-4","1.6.4-5","1.6.5-2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.6.5-2ubuntu0.2","binary_name":"libgcrypt20"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2016-6313","severity":[{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3065-1.json"}}],"schema_version":"1.7.5"}