Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Gigabyte Intel Z87 Motherboard Lineup Preview and more
· Microsoft to roll out Xbox dashboard UI alterations before next-gen console
· Adobe Photoshop Express now available for Windows 8 and RT
· GNOME 3.8.2 Released
· Windows 8 is an enterprise 'non-starter' because IT sees no value in changes
· What to Expect from Unity in Ubuntu 13.10
· Analysts praise Nokia's new Lumia 925
· Best Business Laptops - May 2013 and more
· openSUSE 13.1 Milestone 1 released
· How to Install Cinnamon 1.8 on Ubuntu 13.04

Upcoming News
· Gigabyte Intel Z87 Motherboard Lineup Preview
· [ANNOUNCE] libchamplain 0.12.4
· [security-announce] SUSE-SU-2013:0810-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0811-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0809-1: important: Security update for Acrobat Reader
· Rosewill RDEE-12002 USB 3.0 Hard Drive Enclosure @ techPowerUp
· ASUS M5A97 R2.0 Motherboard @ Hardware Secrets
· Samsung Galaxy S4 Smartphone Review @ HardwareHeaven.com
· [RHSA-2013:0832-01] Important: kernel security update
· [Tech ARP] Hard Disk Drive Myths Debunked! Rev. 5.1

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6283 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 621 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4473 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 689 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1073 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2006 » USN-393-2: GnuPG2 vulnerabilities

USN-393-2: GnuPG2 vulnerabilities

Posted by Bob on: 12/07/2006 09:40 PM [ Print | 0 comment(s) ]

A new GnuPG2 vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-393-2 December 07, 2006
gnupg2 vulnerabilities
CVE-2006-6169, CVE-2006-6235
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects the following Ubuntu releases:

Ubuntu 6.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.10:
gnupg2 1.9.21-0ubuntu5.2

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

USN-389-1 and USN-393-1 fixed vulnerabilities in gnupg. This update=20
provides the corresponding updates for gnupg2.

Original advisory details:

A buffer overflow was discovered in GnuPG. By tricking a user into=20
running gpg interactively on a specially crafted message, an attacker=20
could execute arbitrary code with the user's privileges. This=20
vulnerability is not exposed when running gpg in batch mode. =20
(CVE-2006-6169)

Tavis Ormandy discovered that gnupg was incorrectly using the stack. =20
If a user were tricked into processing a specially crafted message, an=20
attacker could execute arbitrary code with the user's privileges.
(CVE-2006-6235)


Updated packages for Ubuntu 6.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21-0ubu=
ntu5.2.diff.gz
Size/MD5: 39057 24885457e44f2061c1a2ef98047357d4
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21-0ubu=
ntu5.2.dsc
Size/MD5: 839 5786619a42c6768da183ec2c39d70541
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21.orig=
=2Etar.gz
Size/MD5: 2290952 5a609db8ecc661fb299c0dccd84ad503

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.2_amd64.deb
Size/MD5: 193748 57618f27a79f42a3e9f66705ed0ab151
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.2_amd64.deb
Size/MD5: 787166 9641af8af591a9d61c3d9d77144aa320
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.2_amd64.deb
Size/MD5: 333002 a6d5f35e4fc7dc4c6a837862b269ddc1

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.2_i386.deb
Size/MD5: 176170 3dc1e0b862fbf76905b61b20132812de
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.2_i386.deb
Size/MD5: 737818 ab6d004d7fbf1b0850e6f6f4f09771d4
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.2_i386.deb
Size/MD5: 304798 1d6b309f0690685ffa95d219750033dc

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.2_powerpc.deb
Size/MD5: 190614 16cd71ed4d92b1203806ba50e638e9e0
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.2_powerpc.deb
Size/MD5: 773762 56903ee4d39929254b3a4ac06a56a2c5
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.2_powerpc.deb
Size/MD5: 324332 6b9152bd5753f974161c298d6fd6f894

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.2_sparc.deb
Size/MD5: 174144 2e5e21144005113345e3abeef2b50496
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.2_sparc.deb
Size/MD5: 726244 5dc2d8b804a2a5276344b151a46e1346
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.2_sparc.deb
Size/MD5: 297640 5c27421fb28c63abac748419a05220bb


--D+UG5SQJKkIYNVx0
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFFeHorH/9LqRcGPm0RApCbAJwNssfTCtMs+GKF5cpfaY4vmEJH0wCeOfuz
k4PVbiCwtIDvA6RvUpKYPKE=
=3K74
-----END PGP SIGNATURE-----


Bookmark and Share

« Major Labels Release Songs Minus iTunes, DRM Restrictions · Visual Studio 2005 Team Edition for Database Professionals - Trial Edition »

Linux Compatible » News » December 2006 » USN-393-2: GnuPG2 vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition