Lucene search

K
osvGoogleOSV:DSA-2601-1
HistoryJan 06, 2013 - 12:00 a.m.

gnupg - missing input sanitation

2013-01-0600:00:00
Google
osv.dev
16

EPSS

0.048

Percentile

92.8%

KB Sriram discovered that GnuPG, the GNU Privacy Guard did not
sufficiently sanitise public keys on import, which could lead to
memory and keyring corruption.

The problem affects both version 1, in the gnupg package, and
version two, in the gnupg2 package.

For the stable distribution (squeeze), this problem has been fixed in
version 1.4.10-4+squeeze1 of gnupg and version 2.0.14-2+squeeze1 of
gnupg2.

For the testing distribution (wheezy) and unstable distribution (sid),
this problem has been fixed in version 1.4.12-7 of gnupg and
version 2.0.19-2 of gnupg2.

We recommend that you upgrade your gnupg and/or gnupg2 packages.