IBM Security Bulletin: Vulnerability in libgcrypt affects SmartCloud Entry (CVE-2016-6313 )

GnuPG could provide weaker than expected security, caused by an error in the mixing functions when obtaining 4640 bits from the random number generator.

CVE(s): CVE-2016-6313

Affected product(s) and affected version(s):

IBM SmartCloud Entry 2.3.0 through 2.3.0.4 Appliance fix pack 8,
IBM SmartCloud Entry 2.4.0 through 2.4.0.4 Appliance fix pack 8,
IBM SmartCloud Entry 3.1.0 through 3.1.0.4 Appliance fix pack 23,
IBM SmartCloud Entry 3.2.0 through 3.2.0.4 Appliance fix pack 23

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2psq6Bu
X-Force Database: http://ift.tt/2j0JmCQ



from IBM Product Security Incident Response Team http://ift.tt/2psn0gN