LWN.net Logo

gnupg: false positive signature verification

Package(s):gnupg CVE #(s):CVE-2006-0455
Created:February 17, 2006 Updated:March 10, 2006
Description: Tavis Ormandy noticed that gnupg, the GNU privacy guard - a free PGP replacement, verifies external signatures of files successfully even though they don't contain a signature at all. See this update from the gnuPG team for more information.
Alerts:
SuSE SUSE-SA:2006:014 2006-03-10
SuSE SUSE-SR:2006:005 2006-03-03
SuSE SUSE-SA:2006:013 2006-03-01
Trustix TSLSA-2006-0008 2006-02-17
SuSE SUSE-SA:2006:009 2006-02-20
Gentoo 200602-10 2006-02-18
OpenPKG OpenPKG-SA-2006.001 2006-02-18
Mandriva MDKSA-2006:043 2006-02-17
Fedora FEDORA-2006-116 2006-02-17
Ubuntu USN-252-1 2006-02-17
Debian DSA-978-1 2006-02-17

(Log in to post comments)

gnupg: false positive signature verification

Posted Mar 16, 2006 9:39 UTC (Thu) by mjcox@redhat.com (subscriber, #31775) [Link]

20060315 http://rhn.redhat.com/errata/RHSA-2006-0266.html

gnupg: false positive signature verification

Posted Mar 16, 2006 16:44 UTC (Thu) by ris (editor, #5) [Link]

RHSA-2006:0266-01 fixes CVE-2006-0455 and CVE-2006-0049
This alert has been linked to http://lwn.net/Vulnerabilities/175416/ (CVE-2006-0049)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds