Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2022-0260 Important: libjpeg-turbo Buffer Overflow Vulnerability

mageia
Calendar Grey July 13, 2022
Dist Mageia Esm H88
Mageia has released updates for various packages to address vulnerabilities related to gnupg2 signature forgery threats, as highlighted in the most recent advisory.
In unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery vi...

Summary

In unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line. (CVE-2022-34903)

References

- https://bugs.mageia.org/show_bug.cgi?id=30591

- https://lists.gnupg.org/pipermail/gnupg-announce/2022q3/000474.html

- https://nvd.nist.gov/vuln/detail/CVE-2022-34903

- https://www.cve.org/CVERecord?id=CVE-2022-34903

Resolution

SRPMS

- 8/core/gnupg2-2.2.36-1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 13 Jul 2022
URL: https://advisories.mageia.org/MGASA-2022-0259.html
Type: security
CVE: CVE-2022-34903

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here