Revision Date: | 2013-10-10 | Version: | 1 | Title: | CVE-2013-4345 on Ubuntu 16.04 LTS (xenial) - medium. | Description: | Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data. Stephan Mueller reported an error in the Linux kernel's ansi cprng random number generator. This flaw makes it easier for a local attacker to break cryptographic protections.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2013-4345
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
linux package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
OR linux-aws package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1001.10').
OR linux-flo: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'abandoned').
OR linux-gke package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1003.3').
OR linux-goldfish: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'abandoned').
OR linux-hwe package in xenial, is related to the CVE in some way and has been fixed (note: '4.8.0-36.36~16.04.1').
OR linux-mako: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'abandoned').
OR linux-meta package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
OR linux-meta-aws package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1001.10').
OR linux-meta-hwe package in xenial, is related to the CVE in some way and has been fixed (note: '4.8.0-36.36~16.04.1').
OR linux-meta-raspi2 package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-1013.19').
OR linux-meta-snapdragon package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1012.12').
OR linux-raspi2 package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-1013.19').
OR linux-signed package in xenial, is related to the CVE in some way and has been fixed (note: '4.2.0-16.19').
OR linux-signed-hwe package in xenial, is related to the CVE in some way and has been fixed (note: '4.8.0-36.36~16.04.1').
OR linux-snapdragon package in xenial, is related to the CVE in some way and has been fixed (note: '4.4.0-1012.12').
|
|