|
Test ID: | 1.3.6.1.4.1.25623.1.0.54463 |
Category: | FreeBSD Local Security Checks |
Title: | FreeBSD Ports: gnupg |
Summary: | FreeBSD Ports: gnupg |
Description: | Description: The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: gnupg CVE-2005-0366 The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed. Solution: Update your system with the appropriate patches or software upgrades. http://eprint.iacr.org/2005/033 http://lists.gnupg.org/pipermail/gnupg-announce/2005q1/000191.html http://www.vuxml.org/freebsd/8375a73f-01bf-11da-bc08-0001020eed82.html CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
BugTraq ID: 12529 Common Vulnerability Exposure (CVE) ID: CVE-2005-0366 http://eprint.iacr.org/2005/033 http://eprint.iacr.org/2005/033.pdf http://www.gentoo.org/security/en/glsa/glsa-200503-29.xml http://www.mandriva.com/security/advisories?name=MDKSA-2005:057 SuSE Security Announcement: SUSE-SR:2005:007 (Google Search) http://www.novell.com/linux/security/advisories/2005_07_sr.html CERT/CC vulnerability note: VU#303094 http://www.kb.cert.org/vuls/id/303094 http://www.securityfocus.com/bid/12529 http://www.osvdb.org/13775 http://securitytracker.com/id?1013166 |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 58962 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|