Ubuntu alert USN-5431-1 (gnupg2)
From: | David Fernandez Gonzalez <david.fernandezgonzalez@canonical.com> | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-5431-1] GnuPG vulnerability | |
Date: | Mon, 30 May 2022 11:17:44 +0200 | |
Message-ID: | <cb508ed5-cd66-985f-9c0b-f0a0f91ec401@canonical.com> |
========================================================================== Ubuntu Security Notice USN-5431-1 May 30, 2022 gnupg2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: GnuPG could be made to stop responding. Software Description: - gnupg2: GNU privacy guard - a free PGP replacement Details: It was discovered that GnuPG was not properly processing keys with large amounts of signatures. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: gnupg 2.2.4-1ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5431-1 CVE-2019-13050 Package Information: https://launchpad.net/ubuntu/+source/gnupg2/2.2.4-1ubuntu1.5