Oval Definition:oval:org.mitre.oval:def:24793
Revision Date:2014-09-08Version:3
Title:SUSE-SU-2013:1578-1 -- Security update for gpg
Description:This GnuPG LTSS roll-up update fixes two security issues: * CVE-2013-4351: GnuPG treated no-usage-permitted keysas all-usages-permitted. * CVE-2013-4402: An infinite recursion in thecompressed packet parser was fixed. * CVE-2013-4242: GnuPG allowed local users to obtainprivate RSA keys via a cache side-channel attack involvingthe L3 cache, aka Flush+Reload. * CVE-2012-6085: The read_block function ing10/import.c in GnuPG 1.4.x, when importing a key, allowedremote attackers to corrupt the public keyring database orcause a denial of service (application crash) via a craftedlength field of an OpenPGP packet.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-6085
CVE-2013-4242
CVE-2013-4351
CVE-2013-4402
SUSE-SU-2013:1578-1
Platform(s):SUSE Linux Enterprise Server 10
Product(s):gpg
Definition Synopsis
  • SUSE Linux Enterprise Server 10 is installed
  • AND gpg RPM is earlier than 0:1.4.2-23.27.1
  • BACK