Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE 5.2: 2022:2546-1 Important: gpg2 Status Injection Issue

opensuse
Calendar Grey September 1, 2022
Dist Opensuse Esm H88
The latest gpg2 revision tackles a critical vulnerability related to status injection, significantly enhancing encryption protocols for openSUSE customers.
An update that solves one vulnerability and has one errata is now available

Description

This update for gpg2 fixes the following issues:

- CVE-2022-34903: Fixed a status injection vulnerability (bsc#1201225).

- Use AES as default cipher instead of 3DES when we are in FIPS mode.

(bsc#1196125)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap Micro 5.2:

zypper in -t patch openSUSE-Leap-Micro-5.2-2022-2546=1

Package List

- openSUSE Leap Micro 5.2 (aarch64 x86_64):

gpg2-2.2.27-150300.3.5.1

gpg2-debuginfo-2.2.27-150300.3.5.1

gpg2-debugsource-2.2.27-150300.3.5.1

References

https://www.suse.com/security/cve/CVE-2022-34903.html

https://bugzilla.suse.com/1196125

https://bugzilla.suse.com/1201225

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:2546-1
Rating: important
Affected Products: openSUSE Leap Micro 5.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here