Oval Definition:oval:org.mitre.oval:tst:32673
Comment:gnupg is earlier than 0:1.2.1-15
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:13847
State:oval:org.mitre.oval:ste:9496
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:10063
V
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
2013-04-29
oval:org.mitre.oval:def:10084
V
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".
2013-04-29
BACK