| Description: | The remote host is missing an update to gpgme1.0 announced via advisory USN-432-2.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 6.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
USN-432-1 fixed a vulnerability in GnuPG. This update provides the corresponding updates for GnuPG2 and the GPGME library.
Original advisory details:
Gerardo Richarte from Core Security Technologies discovered that when gnupg is used without --status-fd, there is no way to distinguish initial unsigned messages from a following signed message. An attacker could inject an unsigned message, which could fool the user into thinking the message was entirely signed by the original sender.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: libgpgme11 1.1.0-1ubuntu0.1
Ubuntu 6.10: gnupg2 1.9.21-0ubuntu5.3 libgpgme11 1.1.2-2ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-432-2
Risk factor : Medium |