Your submission was sent successfully! Close

USN-264-1: gnupg vulnerability

4 April 2006

gnupg vulnerability

Releases

Details

Tavis Ormandy discovered a flaw in gnupg's signature verification. In
some cases, certain invalid signature formats could cause gpg to
report a 'good signature' result for auxiliary unsigned data which was
prepended or appended to the checked message part.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.10
  • gnupg -
Ubuntu 5.04
  • gnupg -
Ubuntu 4.10
  • gnupg -

In general, a standard system update will make all the necessary changes.

References