libgcrypt: Multiple vulnerabilities Multiple vulnerabilities have been fixed in libgcrypt,the worst of which results in predictable output from the random number generator. libgcrypt 2016-10-10 2016-10-10 541564 559942 574268 591534 remote 1.7.3 1.7.3

libgcrypt is a general purpose cryptographic library derived out of GnuPG.

Multiple vulnerabilities have been discovered in libgcrypt. Please review the CVE identifiers referenced below for details.

Side-channel attacks can leak private key information. A separate critical bug allows an attacker who obtains 4640 bits from the RNG to trivially predict the next 160 bits of output.

There is no known workaround at this time.

All libgcrypt users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libgcrypt-1.7.3"
CVE-2014-3591 CVE-2015-0837 CVE-2015-7511 CVE-2016-6313 Factoring RSA Keys With TLS Perfect Forward Secrecy BlueKnight K_F