Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora Core 4: FEDORA-2006-147 Critical: GnuPG Cryptographic Flaw

fedora
Calendar Grey March 13, 2006
Dist Fedora Esm H88
A recent patch for GnuPG addresses a security vulnerability that could permit the extraction of unsigned content from authenticated messages.
Tavis Ormandy discovered a flaw in the way GnuPG verifies cryptographically signed data with inline signatures

Summary

GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and

creating digital signatures. GnuPG has advanced key management

capabilities and is compliant with the proposed OpenPGP Internet

standard described in RFC2440. Since GnuPG doesn't use any patented

algorithm, it is not compatible with any version of PGP2 (PGP2.x uses

only IDEA for symmetric-key encryption, which is patented worldwide).

Tavis Ormandy discovered a flaw in the way GnuPG verifies

cryptographically signed data with inline signatures. It is

possible for an attacker to add unsigned text to a signed

message in such a way so that when the signed text is

extracted, the unsigned text is extracted as well, appearing

as if it had been signed. The Common Vulnerabilities and

Exposures project assigned the name CVE-2006-0049 to this issue.

- update to 1.4.2.2 to fix detection of unsigned data (CVE-2006-0049, #184557)

399347d86a34ec777de3fa46a8931774bf425679 SRPMS/gnupg-1.4.2.2-1.src.rpm

a42396ca1e3828f725c903f3a38a03096bea3e91 ppc/gnupg-1.4.2.2-1.ppc.rpm

d080a2ac636e7200970f7bca2cde0897d9949910 ppc/debug/gnupg-debuginfo-1.4.2.2-1.ppc.rpm

5f0cb70184126988f240c3487fe38ed37bae0df6 x86_64/gnupg-1.4.2.2-1.x86_64.rpm

bc935e3520882a6461ddb27318fa909ebd9d47b4 x86_64/debug/gnupg-debuginfo-1.4.2.2-1.x86_64.rpm

fa64b2b2645982e7abe49a2ca0ae85c899d65eff i386/gnupg-1.4.2.2-1.i386.rpm

8c146199cc14d0dbfaebbc2c4b8fbeb17e9589f1 i386/debug/gnupg-debuginfo-1.4.2.2-1.i386.rpm

This update can be installed with the 'yum' update program. Use 'yum update

package-name' at the command line. For more information, refer to 'Managing

Software with yum,' available at .

fedora-announce-list mailing list

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: gnupg
Version: 1.4.2.2
Release: 1
Summary: A GNU utility for secure communication and data storage.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here