Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Slackware: 2014-175-02 Critical: GnuPG Denial Of Service

slackware
Calendar Grey June 24, 2014
Dist Slackware Esm H88
Recent updates to gnupg packages in Slackware address a critical denial of service vulnerability found in several versions. It is advisable to upgrade without delay.
New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/gnupg-1.4.17-i486-1_slack14.1.txz: Upgraded. This release includes a security fix to stop a denial of service using garbled compressed data packets which can be used to put gpg into an infinite loop. For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-4617 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: 2a3448e3d468203be5458c357d6f05ef gnupg-1.4.17-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: bd2c80dd4d2ae5a28c49026070bc7800 gnupg-1.4.17-x86_64-1_slack13.0.txz
Slackware 13.1 package: 0e49f54235b05a9b981af034c490b39d gnupg-1.4.17-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: becc38f574d9af131e667e573b410af9 gnupg-1.4.17-x86_64-1_slack13.1.txz
Slackware 13.37 package: f807d51cb4d1474aa41979c0a933ca1d gnupg-1.4.17-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: a7e2270d3992e827c7f62d3e64218e16 gnupg-1.4.17-x86_64-1_slack13.37.txz
Slackware 14.0 package: bbc9a2603c167222daeac34fcdbfd15d gnupg-1.4.17-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: e3fbe6149e0bad38952225c602788469 gnupg-1.4.17-x86_64-1_slack14.0.txz
Slackware 14.1 package: 42252dd42d19619ae2d40f85061f4cfc gnupg-1.4.17-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 032338eac243499017516e4d9bd8cece gnupg-1.4.17-x86_64-1_slack14.1.txz
Slackware -current package: 4eb3e45b7337197ff3281335147b2556 n/gnupg-1.4.17-i486-1.txz
Slackware x86_64 -current package: f09b029cd5daa846a9e87bc4699cda81 n/gnupg-1.4.17-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg gnupg-1.4.17-i486-1_slack14.1.txz

Related News

Your message here