Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12233
HistoryJan 15, 2019 - 9:14 a.m.

Information Leakage

2019-01-1509:14:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.007 Low

EPSS

Percentile

80.6%

The libgcrypt library is vulnerable to information leakage. The vulnerability exists because of a flaw in the libgcrypt PRNG (Pseudo-Random Number Generator), leaking the first 580 bytes of the PRNG output which allows the attacker to guess the following 20 bytes.