Lucene search

K
ubuntuUbuntuUSN-1987-1
HistoryOct 09, 2013 - 12:00 a.m.

GnuPG vulnerabilities

2013-10-0900:00:00
ubuntu.com
49

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

9

Confidence

High

EPSS

0.045

Percentile

92.5%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • gnupg - GNU privacy guard - a free PGP replacement
  • gnupg2 - GNU privacy guard - a free PGP replacement

Details

Daniel Kahn Gillmor discovered that GnuPG treated keys with empty usage
flags as being valid for all usages. (CVE-2013-4351)

Taylor R Campbell discovered that GnuPG incorrectly handled certain OpenPGP
messages. If a user or automated system were tricked into processing a
specially-crafted message, GnuPG could consume resources, resulting in a
denial of service. (CVE-2013-4402)

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchgnupg2< 2.0.19-2ubuntu1.1UNKNOWN
Ubuntu13.04noarchgnupg-agent< 2.0.19-2ubuntu1.1UNKNOWN
Ubuntu13.04noarchgpgsm< 2.0.19-2ubuntu1.1UNKNOWN
Ubuntu13.04noarchscdaemon< 2.0.19-2ubuntu1.1UNKNOWN
Ubuntu13.04noarchgnupg< 1.4.12-7ubuntu1.2UNKNOWN
Ubuntu13.04noarchgnupg-curl< 1.4.12-7ubuntu1.2UNKNOWN
Ubuntu13.04noarchgnupg-udeb< 1.4.12-7ubuntu1.2UNKNOWN
Ubuntu13.04noarchgpgv< 1.4.12-7ubuntu1.2UNKNOWN
Ubuntu13.04noarchgpgv-udeb< 1.4.12-7ubuntu1.2UNKNOWN
Ubuntu12.10noarchgnupg2< 2.0.17-2ubuntu3.2UNKNOWN
Rows per page:
1-10 of 331

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

9

Confidence

High

EPSS

0.045

Percentile

92.5%