Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Windows 8 is an enterprise 'non-starter' because IT sees no value in changes
· What to Expect from Unity in Ubuntu 13.10
· Analysts praise Nokia's new Lumia 925
· Best Business Laptops - May 2013 and more
· openSUSE 13.1 Milestone 1 released
· How to Install Cinnamon 1.8 on Ubuntu 13.04
· Tim Cook Shares Details About New 'Made in USA' Mac Model
· Surface Pro firmware and driver pack - May 2013
· More Surface Pro launch dates revealed in Europe
· Apple Updates iTunes to Version 11.0.3 With New MiniPlayer and Improvements

Upcoming News
· Gigabyte Intel Z87 Motherboard Lineup Preview
· [ANNOUNCE] libchamplain 0.12.4
· [security-announce] SUSE-SU-2013:0810-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0811-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0809-1: important: Security update for Acrobat Reader
· Rosewill RDEE-12002 USB 3.0 Hard Drive Enclosure @ techPowerUp
· ASUS M5A97 R2.0 Motherboard @ Hardware Secrets
· Samsung Galaxy S4 Smartphone Review @ HardwareHeaven.com
· [RHSA-2013:0832-01] Important: kernel security update
· [Tech ARP] Hard Disk Drive Myths Debunked! Rev. 5.1

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Enjoy Preakness Stakes live stream online
by: charles0120r
on: 2013-05-18 10:29
0 replies, 0 views

· Watch Preakness Stakes 2013 online
by: charles0120r
on: 2013-05-18 10:28
0 replies, 0 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6278 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 616 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4471 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2007 » USN-432-2: GnuPG2, GPGME vulnerability

USN-432-2: GnuPG2, GPGME vulnerability

Posted by Bob on: 03/13/2007 04:50 PM [ Print | 0 comment(s) ]

A new GnuPG2, GPGME vulnerability update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-432-2 March 13, 2007
gnupg2, gpgme1.0 vulnerability
CVE-2007-1263
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
libgpgme11 1.1.0-1ubuntu0.1

Ubuntu 6.10:
gnupg2 1.9.21-0ubuntu5.3
libgpgme11 1.1.2-2ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

USN-432-1 fixed a vulnerability in GnuPG. This update provides the
corresponding updates for GnuPG2 and the GPGME library.

Original advisory details:

Gerardo Richarte from Core Security Technologies discovered that when
gnupg is used without --status-fd, there is no way to distinguish
initial unsigned messages from a following signed message. An attacker
could inject an unsigned message, which could fool the user into
thinking the message was entirely signed by the original sender.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.0-1=
ubuntu0.1.diff.gz
Size/MD5: 35741 47d6ee190ee0522b45b96dfea1aec369
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.0-1=
ubuntu0.1.dsc
Size/MD5: 659 536b60523f53fe45e9a715fee633fb8e
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.0.o=
rig.tar.gz
Size/MD5: 862122 dc180e1c2b3b13cf3b16b9586e8509ac

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.0-1ubuntu0.1_amd64.deb
Size/MD5: 343394 ca1cd44964639c3b1ab517d71f02be7c
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.0=
-1ubuntu0.1_amd64.deb
Size/MD5: 185096 686c695bf758bdb35eb0277596b5d967

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.0-1ubuntu0.1_i386.deb
Size/MD5: 316162 787bcf93b93d4d846c4278caee3f298a
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.0=
-1ubuntu0.1_i386.deb
Size/MD5: 164356 a3e2c02f67687ed53c80023159a08513

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.0-1ubuntu0.1_powerpc.deb
Size/MD5: 329614 079a0ad9f7775de82b21bc8cd8b7e96b
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.0=
-1ubuntu0.1_powerpc.deb
Size/MD5: 178434 1430154f3bda638d607d3d00c9da736c

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.0-1ubuntu0.1_sparc.deb
Size/MD5: 316166 687a5a1e91979f26cf0453315e10aa85
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.0=
-1ubuntu0.1_sparc.deb
Size/MD5: 169754 90558aac05b3f71c98dcf5e089dfa37b

Updated packages for Ubuntu 6.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21-0ubu=
ntu5.3.diff.gz
Size/MD5: 40536 57bef9fd8e37b8d1f0c09c7cb6a1b4b6
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21-0ubu=
ntu5.3.dsc
Size/MD5: 839 3830cb1f96959bebba4560bf56cfb865
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gnupg2_1.9.21.orig=
.tar.gz
Size/MD5: 2290952 5a609db8ecc661fb299c0dccd84ad503
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.2-2=
ubuntu0.1.diff.gz
Size/MD5: 582785 ffc28a1ddf242c1434054c611b3e56e7
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.2-2=
ubuntu0.1.dsc
Size/MD5: 744 59ff64cec62d3259528e4dcb314115b0
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/gpgme1.0_1.1.2.o=
rig.tar.gz
Size/MD5: 881432 c712ca39c3553573f15cd01e6edb8b68

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.3_amd64.deb
Size/MD5: 193872 094402a2b5d64a699a9b8da5f47891f1
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.3_amd64.deb
Size/MD5: 787500 8198d070a8589a47f9b0c6893b101d89
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.3_amd64.deb
Size/MD5: 333136 deb90b54b5d8ff98e2f8f3f8a96c4896
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.2-2ubuntu0.1_amd64.deb
Size/MD5: 349736 8b6ba64e232718d85b20e01152d5e0b6
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.2=
-2ubuntu0.1_amd64.deb
Size/MD5: 188434 7f594bfa7c5a223fbc48dcd5063239f4

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.3_i386.deb
Size/MD5: 176266 4e191490d03c78bb16ae76ffdcc1f4ce
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.3_i386.deb
Size/MD5: 738282 f26ac977c08ecc691c5428367b4b1196
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.3_i386.deb
Size/MD5: 304926 124b1f54edc4902ddc9656fb6d56e2eb
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.2-2ubuntu0.1_i386.deb
Size/MD5: 329932 fc9e1af3ae706db0bc106607f6f8c0d3
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.2=
-2ubuntu0.1_i386.deb
Size/MD5: 174936 c1f8f21e0adf999ea3098b3aaab4882e

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.3_powerpc.deb
Size/MD5: 190746 2da9f0306a14651ece00b85d41700391
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.3_powerpc.deb
Size/MD5: 774174 fa48b523bc15d9e3590ff0739bceafb4
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.3_powerpc.deb
Size/MD5: 324472 ef82785a6bdaea9009669d3024f6b0b4
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.2-2ubuntu0.1_powerpc.deb
Size/MD5: 335252 ec105374c75dccf66afcfe154d34387f
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.2=
-2ubuntu0.1_powerpc.deb
Size/MD5: 182786 915534115d51065f3cfebc2b02b637e7

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg-agent_1.=
9.21-0ubuntu5.3_sparc.deb
Size/MD5: 174274 73230ada924427a5d5fc230b7d625b64
http://security.ubuntu.com/ubuntu/pool/universe/g/gnupg2/gnupg2_1.9.21-=
0ubuntu5.3_sparc.deb
Size/MD5: 726564 3b0f3eb59acd4157913885ba1461567e
http://security.ubuntu.com/ubuntu/pool/main/g/gnupg2/gpgsm_1.9.21-0ubun=
tu5.3_sparc.deb
Size/MD5: 297776 8c76049329431405229dce046656b6b6
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11-dev_1=
.1.2-2ubuntu0.1_sparc.deb
Size/MD5: 323808 8668135508773a2f41fde93153d786ff
http://security.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.1.2=
-2ubuntu0.1_sparc.deb
Size/MD5: 174140 9d305501f27c38e624b95788f6945736


--T4IYkFBVPN84tP7K
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF9sWZH/9LqRcGPm0RAn10AKClkYfSM6cYawlATNv/1dUP2ty/0gCeNZix
SMNv0UoyeGdrtv6vKEJSOks=
=JhQJ
-----END PGP SIGNATURE-----


Bookmark and Share

« Analyst: iPhone Tech May Propel Apple Growth · iTunes Draws Ire of EU Commissioner »

Linux Compatible » News » March 2007 » USN-432-2: GnuPG2, GPGME vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition