gnupg-1.4.5-18.AXS3

エラータID: AXSA:2013-679:01

Release date: 
Monday, November 25, 2013 - 13:43
Subject: 
gnupg-1.4.5-18.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide).

Security issues fixed with this release:

• CVE-2012-6085
The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

• CVE-2013-4242
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.

• CVE-2013-4351
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

• CVE-2013-4402
GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gnupg-1.4.5-18.AXS3.src.rpm
    MD5: bf9f6e88f4c84b7a5e5fc791078f168b
    SHA-256: 0810df4be321be88061678a704e2213c0f12e5c856f182007d0dc78941f1ea17
    Size: 2.98 MB

Asianux Server 3 for x86
  1. gnupg-1.4.5-18.AXS3.i386.rpm
    MD5: 4702ac6d0f3b22f81662ba5e715d50c4
    SHA-256: a2f482fff0d0c46d0c3d56e200f548abf3f04412d930d075b276158b159122c8
    Size: 1.83 MB

Asianux Server 3 for x86_64
  1. gnupg-1.4.5-18.AXS3.x86_64.rpm
    MD5: c328fb63a37151406e99bf304321d102
    SHA-256: 1e845477cfbc9c49d0ed819786ebea76b2e3cb62ef5c0d6f74cad04bdea943ee
    Size: 1.82 MB