Lucene search

K
ubuntuUbuntuUSN-264-1
HistoryApr 04, 2006 - 12:00 a.m.

gnupg vulnerability

2006-04-0400:00:00
ubuntu.com
24

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.006

Percentile

78.5%

Releases

  • Ubuntu 5.10
  • Ubuntu 5.04
  • Ubuntu 4.10

Details

Tavis Ormandy discovered a flaw in gnupg’s signature verification. In
some cases, certain invalid signature formats could cause gpg to
report a ‘good signature’ result for auxiliary unsigned data which was
prepended or appended to the checked message part.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.006

Percentile

78.5%