Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54080
Category:SuSE Local Security Checks
Title:SuSE Security Advisory SUSE-SA:2003:048 (gpg)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory SUSE-SA:2003:048.

The gnupg (the SUSE package is named gpg) package is the most widely
used software for cryptographic encryption/decryption of data.

Two independent errors have been found in gpg (GnuPG) packages as shipped
with SUSE products:

1) A format string error in the client code that does key retrieval
from a (public) key server

2) A cryptographic error in gpg that results in a compromise of a
cryptographic keypair if ElGamal signing keys have been used for
generating the key.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

https://secure1.securityspace.com/smysecure/catid.html?in=SUSE-SA:2003:048

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: BugTraq ID: 9115
Common Vulnerability Exposure (CVE) ID: CVE-2003-0971
http://www.securityfocus.com/bid/9115
Bugtraq: 20031127 GnuPG's ElGamal signing keys compromised (Google Search)
http://marc.info/?l=bugtraq&m=106995769213221&w=2
CERT/CC vulnerability note: VU#940388
http://www.kb.cert.org/vuls/id/940388
Conectiva Linux advisory: CLA-2003:798
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000798
Debian Security Information: DSA-429 (Google Search)
http://www.debian.org/security/2004/dsa-429
http://www.mandriva.com/security/advisories?name=MDKSA-2003:109
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982
http://www.redhat.com/support/errata/RHSA-2003-390.html
http://www.redhat.com/support/errata/RHSA-2003-395.html
http://secunia.com/advisories/10304
http://secunia.com/advisories/10349
http://secunia.com/advisories/10399
http://secunia.com/advisories/10400
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
SuSE Security Announcement: SuSE-SA:2003:048 (Google Search)
http://www.novell.com/linux/security/advisories/2003_048_gpg.html
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.