|
|
Subscribe / Log in / New account

Mageia alert MGASA-2025-0133 (gnupg2)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2025-0133: Updated gnupg2 packages fix security vulnerabilitiy
Date:  Sat, 12 Apr 2025 06:24:30 +0200
Message-ID:  <20250412042430.C66AEA0153@duvel.mageia.org>
Archive-link:  Article

MGASA-2025-0133 - Updated gnupg2 packages fix security vulnerabilitiy Publication date: 12 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0133.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-30258 Description: In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS". (CVE-2025-30258) References: - https://bugs.mageia.org/show_bug.cgi?id=34165 - https://ubuntu.com/security/notices/USN-7412-1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-3... SRPMS: - 9/core/gnupg2-2.3.8-1.3.mga9


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds