gnupg2-2.0.14-6.AXS4

エラータID: AXSA:2014-005:01

Release date: 
Tuesday, March 4, 2014 - 12:35
Subject: 
gnupg2-2.0.14-6.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440 and the S/MIME standard as described by several RFCs.

GnuPG 2.0 is a newer version of GnuPG with additional support for S/MIME. It has a different design philosophy that splits functionality up into several modules. The S/MIME and smartcard functionality is provided by the gnupg2-smime package.

Security issues fixed with this release:

• CVE-2012-6085
The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

• CVE-2013-4351
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

• CVE-2013-4402
GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gnupg2-2.0.14-6.AXS4.src.rpm
    MD5: 758ce39b7ddf087e1b88f6971a9452b4
    SHA-256: e1203c4894d7aba5c4dc8e5d9468d165f0f6a23fa2860fc92746c7970a118cd0
    Size: 3.82 MB

Asianux Server 4 for x86
  1. gnupg2-2.0.14-6.AXS4.i686.rpm
    MD5: a1f16dc7c581e4660cb816c7acbf0975
    SHA-256: 9d1d649477cd67c2a90441a64ed8f5502307f42393682ef7886cdd15ad853d9e
    Size: 1.56 MB

Asianux Server 4 for x86_64
  1. gnupg2-2.0.14-6.AXS4.x86_64.rpm
    MD5: a996bf0b05b4a913740b261eb5360474
    SHA-256: 939da25d69668bd6f1404ff7a9e47c8b1d96585fef24e23ce524873d4b42cef8
    Size: 1.58 MB