Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702601
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2601-1 (gnupg, gnupg2 - missing input sanitation)
Summary:KB Sriram discovered that GnuPG, the GNU Privacy Guard did not;sufficiently sanitise public keys on import, which could lead to;memory and keyring corruption.;;The problem affects both version 1, in the gnupg package, and;version two, in the gnupg2;package.
Description:Summary:
KB Sriram discovered that GnuPG, the GNU Privacy Guard did not
sufficiently sanitise public keys on import, which could lead to
memory and keyring corruption.

The problem affects both version 1, in the gnupg package, and
version two, in the gnupg2
package.

Affected Software/OS:
gnupg, gnupg2 on Debian Linux

Solution:
For the stable distribution (squeeze), this problem has been fixed in
version 1.4.10-4+squeeze1 of gnupg and version 2.0.14-2+squeeze1 of
gnupg2.

For the testing distribution (wheezy) and unstable distribution (sid),
this problem has been fixed in version 1.4.12-7 of gnupg and
version 2.0.19-2 of gnupg2.

We recommend that you upgrade your gnupg and/or gnupg2 packages.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-6085
BugTraq ID: 57102
http://www.securityfocus.com/bid/57102
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095513.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095516.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:001
https://bugzilla.redhat.com/show_bug.cgi?id=891142
http://www.openwall.com/lists/oss-security/2013/01/01/6
RedHat Security Advisories: RHSA-2013:1459
http://rhn.redhat.com/errata/RHSA-2013-1459.html
http://www.ubuntu.com/usn/USN-1682-1
XForce ISS Database: gnupg-public-keys-code-exec(80990)
https://exchange.xforce.ibmcloud.com/vulnerabilities/80990
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.