Oval Definition:oval:com.redhat.rhsa:def:20100603
Revision Date:2010-08-04Version:635
Title:RHSA-2010:0603: gnupg2 security update (Moderate)
Description:The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with the proposed OpenPGP Internet standard and the S/MIME standard.

  • A use-after-free flaw was found in the way gpgsm, a Cryptographic Message Syntax (CMS) encryption and signing tool, handled X.509 certificates with a large number of Subject Alternate Names. A specially-crafted X.509 certificate could, when imported, cause gpgsm to crash or, possibly, execute arbitrary code. (CVE-2010-2547)

    All gnupg2 users should upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-2547
    RHSA-2010:0603
    RHSA-2010:0603-01
    RHSA-2010:0603-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND gnupg2 is earlier than 0:2.0.10-3.el5_5.1
  • AND gnupg2 is signed with Red Hat redhatrelease2 key
  • BACK