Lucene search

K
freebsdFreeBSD948921AD-AFBC-11DA-BAD9-02E081235DAB
HistoryMar 09, 2006 - 12:00 a.m.

GnuPG does not detect injection of unsigned data

2006-03-0900:00:00
vuxml.freebsd.org
13

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

78.5%

Werner Koch reports:

In the aftermath of the false positive signature
verfication bug (announced 2006-02-15) more thorough testing
of the fix has been done and another vulnerability has been
detected. This new problem affects the use of gpg for
verification of signatures which are not detached
signatures. The problem also affects verification of
signatures embedded in encrypted messages; i.e. standard use
of gpg for mails.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgnupg< 1.4.2.2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

78.5%