IBM Security Bulletin: Vulnerability in libgcrypt affects SmartCloud Entry (CVE-2016-6313 )
May 12, 2017 10:00 am EDT
Categorized: Medium Severity
GnuPG could provide weaker than expected security, caused by an error in the mixing functions when obtaining 4640 bits from the random number generator.
CVE(s): CVE-2016-6313
Affected product(s) and affected version(s):
IBM SmartCloud Entry 2.3.0 through 2.3.0.4 Appliance fix pack 8,
IBM SmartCloud Entry 2.4.0 through 2.4.0.4 Appliance fix pack 8,
IBM SmartCloud Entry 3.1.0 through 3.1.0.4 Appliance fix pack 23,
IBM SmartCloud Entry 3.2.0 through 3.2.0.4 Appliance fix pack 23
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2psq6Bu
X-Force Database: http://ift.tt/2j0JmCQ
from IBM Product Security Incident Response Team http://ift.tt/2psn0gN