Vulnerability Bulletins

DSA-3649 gnupg - security update

   
Affected software Debian
 
Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute ofTechnology discovered a flaw in the mixing functions of GnuPGs randomnumber generator. An attacker who obtains 4640 bits from the RNG cantrivially predict the next 160 bits of output.

More info:

https://www.debian.org/security/2016/dsa-3649