Lucene search

K
slackwareSlackware Linux ProjectSSA-2022-188-01
HistoryJul 07, 2022 - 11:06 p.m.

[slackware-security] gnupg2

2022-07-0723:06:39
Slackware Linux Project
www.slackware.com
16

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

0.004 Low

EPSS

Percentile

74.4%

New gnupg2 packages are available for Slackware 15.0 and -current to
fix a security issue.

Here are the details from the Slackware 15.0 ChangeLog:

patches/packages/gnupg2-2.2.36-i586-1_slack15.0.txz: Upgraded.
g10: Fix possibly garbled status messages in NOTATION_DATA. This bug could
trick GPGME and other parsers to accept faked status lines.
For more information, see:
https://vulners.com/cve/CVE-2022-34903
(* Security fix *)

Where to find the new packages:

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/gnupg2-2.2.36-i586-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/gnupg2-2.2.36-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/gnupg2-2.2.36-i586-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/gnupg2-2.2.36-x86_64-1.txz

MD5 signatures:

Slackware 15.0 package:
22b2df4b784f974f59ab3c7e0e96882b gnupg2-2.2.36-i586-1_slack15.0.txz

Slackware x86_64 15.0 package:
8d280d3920913c18a6b32ef235f6cd3d gnupg2-2.2.36-x86_64-1_slack15.0.txz

Slackware -current package:
676bb996c5c8a2ca48466e3f0f08d977 n/gnupg2-2.2.36-i586-1.txz

Slackware x86_64 -current package:
2f141ef1043b9ff7915d300f3702a52c n/gnupg2-2.2.36-x86_64-1.txz

Installation instructions:

Upgrade the package as root:
> upgradepkg gnupg2-2.2.36-i586-1_slack15.0.txz

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

0.004 Low

EPSS

Percentile

74.4%