Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.120196
Categoría:Amazon Linux Local Security Checks
Título:Amazon Linux: Security Advisory (ALAS-2013-236)
Resumen:The remote host is missing an update for the 'gnupg' package(s) announced via the ALAS-2013-236 advisory.
Descripción:Summary:
The remote host is missing an update for the 'gnupg' package(s) announced via the ALAS-2013-236 advisory.

Vulnerability Insight:
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.

Affected Software/OS:
'gnupg' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-4351
DSA-2773
http://www.debian.org/security/2013/dsa-2773
DSA-2774
http://www.debian.org/security/2013/dsa-2774
RHSA-2013:1459
http://rhn.redhat.com/errata/RHSA-2013-1459.html
USN-1987-1
http://ubuntu.com/usn/usn-1987-1
[oss-security] 20130913 Re: GnuPG treats no-usage-permitted keys as all-usages-permitted
http://www.openwall.com/lists/oss-security/2013/09/13/4
http://thread.gmane.org/gmane.comp.encryption.gpg.devel/17712/focus=18138
https://bugzilla.redhat.com/show_bug.cgi?id=1010137
openSUSE-SU-2013:1526
http://lists.opensuse.org/opensuse-updates/2013-10/msg00003.html
openSUSE-SU-2013:1532
http://lists.opensuse.org/opensuse-updates/2013-10/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-4402
Debian Security Information: DSA-2773 (Google Search)
Debian Security Information: DSA-2774 (Google Search)
http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000334.html
http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000333.html
RedHat Security Advisories: RHSA-2013:1459
SuSE Security Announcement: openSUSE-SU-2013:1546 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00020.html
SuSE Security Announcement: openSUSE-SU-2013:1552 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00025.html
http://www.ubuntu.com/usn/USN-1987-1
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.