Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 14.04 LTS: USN-2021-2 Critical: Libgcrypt Vulnerability

ubuntu
Calendar Grey September 17, 2012
Scroller Ubuntu
A GnuPG flaw enables malicious actors to deceive users into retrieving erroneous keys from key repositories across various Ubuntu versions.
GnuPG could be tricked into downloading a different key when downloading from a key server.

Summary

GnuPG could be tricked into downloading a different key when downloading

from a key server.

Software Description:

- gnupg: GNU privacy guard - a free PGP replacement

- gnupg2: GNU privacy guard - a free PGP replacement

Details:

It was discovered that GnuPG used a short ID when downloading keys from a

keyserver, even if a long ID was requested. An attacker could possibly use

this to return a different key with a duplicate short key id.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  gnupg                           1.4.11-3ubuntu2.1
  gnupg2                          2.0.17-2ubuntu2.12.04.1

Ubuntu 11.10:
  gnupg                           1.4.11-3ubuntu1.11.10.1
  gnupg2                          2.0.17-2ubuntu2.11.10.1

Ubuntu 11.04:
  gnupg                           1.4.11-3ubuntu1.11.04.1
  gnupg2                          2.0.14-2ubuntu1.2

Ubuntu 10.04 LTS:
  gnupg                           1.4.10-2ubuntu1.1
  gnupg2                          2.0.14-1ubuntu1.4

Ubuntu 8.04 LTS:
  gnupg                           1.4.6-2ubuntu5.1
  gnupg2                          2.0.7-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1570-1

https://bugs.launchpad.net/ubuntu/+source/software-properties/+bug/1016643

Severity
critical
Lowest
Low
Medium
High
Critical

September 17, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.