Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· CompatDB Updates 05/22/13
· Removing and Wiping Drivers Guide and more
· Windows Server 2012 Essentials SDK Installer 1.1
· Xbox One hardware and specs: 8-core CPU, 8GB RAM, 500GB hard drive and more
· Tim Cook: US-made Macs will be assembled in Texas
· Microsoft software satisfaction slumps
· Photos of Likely 802.11ac 'Gigabit Wi-Fi' Card From Next-Generation iMac Surface
· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises

Upcoming News
· i-Mego Throne Gold Over Ear Headphones Review @ TestFreaks
· Xbox One: Entertainment Hub First, Gaming Console Second -- But Could It Disrupt TV?
· Star Wars: The Old Republic Gaming Mouse Review @ Madshrimps
· Samsung SSD 840 comparison @ Hardwareoverclock.com
· Leawo Total Media Converter Ultimate @ Benchmark Reviews
· Icy Dock FlexCage MB975SP-B 5x3.5" in 3x5.25" HDD Cage Review @ Hi Tech Legion
· Gigabyte Shows Off Upcoming Intel Z87 Motherboards @ Legit Reviews
· [CentOS-announce] CEBA-2013:0846 CentOS 5 xen Update
· [CentOS-announce] CESA-2013:0847 Moderate CentOS 5 kernel Update
· REVIEW: SilverStone AR01 @ PureOverclock

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6426 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 682 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4542 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 752 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1136 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2006 » [Security Announce] [ MDKSA-2006:228 ] - Updated gnupg packages fix vulnerability

[Security Announce] [ MDKSA-2006:228 ] - Updated gnupg packages fix vulnerability

Posted by Bob on: 12/12/2006 03:45 AM [ Print | 0 comment(s) ]

The Mandriva Security Team published a new security update for Mandriva Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2006:228
http://www.mandriva.com/security/
_______________________________________________________________________

Package : gnupg
Date : December 11, 2006
Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0,
Multi Network Firewall 2.0
_______________________________________________________________________

Problem Description:

A "stack overwrite" vulnerability in GnuPG (gpg) allows attackers to
execute arbitrary code via crafted OpenPGP packets that cause GnuPG to
dereference a function pointer from deallocated stack memory.

Updated packages have been patched to correct this issue.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6235
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2006.0:
93c4722a375c1f5e6a05a005722c2611 2006.0/i586/gnupg-1.4.2.2-0.5.20060mdk.i586.rpm
fffa84eb381e5c0db87f230b3c833239 2006.0/i586/gnupg2-1.9.16-4.4.20060mdk.i586.rpm
e5ffb4d9fa64ef83afa9ea1faa287926 2006.0/SRPMS/gnupg-1.4.2.2-0.5.20060mdk.src.rpm
ca942bbd6fcf9ebe78779737d40f14cd 2006.0/SRPMS/gnupg2-1.9.16-4.4.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
745e690087b6ccfc1ca328db1e6f4ebb 2006.0/x86_64/gnupg-1.4.2.2-0.5.20060mdk.x86_64.rpm
85cf60ed2063692019776138d718b233 2006.0/x86_64/gnupg2-1.9.16-4.4.20060mdk.x86_64.rpm
e5ffb4d9fa64ef83afa9ea1faa287926 2006.0/SRPMS/gnupg-1.4.2.2-0.5.20060mdk.src.rpm
ca942bbd6fcf9ebe78779737d40f14cd 2006.0/SRPMS/gnupg2-1.9.16-4.4.20060mdk.src.rpm

Mandriva Linux 2007.0:
a517dae5c83be0361406388c75098604 2007.0/i586/gnupg-1.4.5-1.2mdv2007.0.i586.rpm
76a286545f5e3122bb65dc812cb9660a 2007.0/i586/gnupg2-1.9.22-2.2mdv2007.0.i586.rpm
b7c1585093289b0adaaf46939ec9f3f8 2007.0/SRPMS/gnupg-1.4.5-1.2mdv2007.0.src.rpm
4f2757b66ac4762ce46ded5329ec7246 2007.0/SRPMS/gnupg2-1.9.22-2.2mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
42c3c8f43d6ff4f67f93b5077b47a4ea 2007.0/x86_64/gnupg-1.4.5-1.2mdv2007.0.x86_64.rpm
f9d3ecb8f0eb5b3721d7cd3a7beeff8a 2007.0/x86_64/gnupg2-1.9.22-2.2mdv2007.0.x86_64.rpm
b7c1585093289b0adaaf46939ec9f3f8 2007.0/SRPMS/gnupg-1.4.5-1.2mdv2007.0.src.rpm
4f2757b66ac4762ce46ded5329ec7246 2007.0/SRPMS/gnupg2-1.9.22-2.2mdv2007.0.src.rpm

Corporate 3.0:
7f7a5ddabcea09044efe1a242b4dee91 corporate/3.0/i586/gnupg-1.4.2.2-0.5.C30mdk.i586.rpm
15c09b82c8c273ec04ae71addf06d010 corporate/3.0/SRPMS/gnupg-1.4.2.2-0.5.C30mdk.src.rpm

Corporate 3.0/X86_64:
0dccce30fd6713dfb228261e10fbb44c corporate/3.0/x86_64/gnupg-1.4.2.2-0.5.C30mdk.x86_64.rpm
15c09b82c8c273ec04ae71addf06d010 corporate/3.0/SRPMS/gnupg-1.4.2.2-0.5.C30mdk.src.rpm

Corporate 4.0:
4908cbaf7474c988c82c2362bfacfa18 corporate/4.0/i586/gnupg-1.4.2.2-0.5.20060mlcs4.i586.rpm
af02670a8a6446a77b8f09c807b7b44c corporate/4.0/i586/gnupg2-1.9.16-4.4.20060mlcs4.i586.rpm
6222c167396ffaec6afa98efca483241 corporate/4.0/SRPMS/gnupg-1.4.2.2-0.5.20060mlcs4.src.rpm
11bb29f2b1f7788f1b15c1f6e4503863 corporate/4.0/SRPMS/gnupg2-1.9.16-4.4.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
d5bafd16b9ad141f87e9259ae74e6538 corporate/4.0/x86_64/gnupg-1.4.2.2-0.5.20060mlcs4.x86_64.rpm
576f3921b0f631ede3da9d9efa541182 corporate/4.0/x86_64/gnupg2-1.9.16-4.4.20060mlcs4.x86_64.rpm
6222c167396ffaec6afa98efca483241 corporate/4.0/SRPMS/gnupg-1.4.2.2-0.5.20060mlcs4.src.rpm
11bb29f2b1f7788f1b15c1f6e4503863 corporate/4.0/SRPMS/gnupg2-1.9.16-4.4.20060mlcs4.src.rpm

Multi Network Firewall 2.0:
58618fe995c74d079c66d5f56aeb8418 mnf/2.0/i586/gnupg-1.4.2.2-0.6.M20mdk.i586.rpm
10bf559c56d1ec0863905d65cc81eb02 mnf/2.0/SRPMS/gnupg-1.4.2.2-0.6.M20mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFFfeF3mqjQ0CJFipgRAg8DAJ9TmZlzdEHqRx/TmNwfcAgMtcd9DwCfVNnm
MlSJow6h1QNNTNWWIoBqVjk=
=g7vl
-----END PGP SIGNATURE-----


Bookmark and Share

« Apple Aperture Update 1.5.2 · Burn 1.62u »

Linux Compatible » News » December 2006 » [Security Announce] [ MDKSA-2006:228 ] - Updated gnupg packages fix vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition