Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120196
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2013-236)
Zusammenfassung:The remote host is missing an update for the 'gnupg' package(s) announced via the ALAS-2013-236 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'gnupg' package(s) announced via the ALAS-2013-236 advisory.

Vulnerability Insight:
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.

Affected Software/OS:
'gnupg' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-4351
DSA-2773
http://www.debian.org/security/2013/dsa-2773
DSA-2774
http://www.debian.org/security/2013/dsa-2774
RHSA-2013:1459
http://rhn.redhat.com/errata/RHSA-2013-1459.html
USN-1987-1
http://ubuntu.com/usn/usn-1987-1
[oss-security] 20130913 Re: GnuPG treats no-usage-permitted keys as all-usages-permitted
http://www.openwall.com/lists/oss-security/2013/09/13/4
http://thread.gmane.org/gmane.comp.encryption.gpg.devel/17712/focus=18138
https://bugzilla.redhat.com/show_bug.cgi?id=1010137
openSUSE-SU-2013:1526
http://lists.opensuse.org/opensuse-updates/2013-10/msg00003.html
openSUSE-SU-2013:1532
http://lists.opensuse.org/opensuse-updates/2013-10/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-4402
Debian Security Information: DSA-2773 (Google Search)
Debian Security Information: DSA-2774 (Google Search)
http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000334.html
http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000333.html
RedHat Security Advisories: RHSA-2013:1459
SuSE Security Announcement: openSUSE-SU-2013:1546 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00020.html
SuSE Security Announcement: openSUSE-SU-2013:1552 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00025.html
http://www.ubuntu.com/usn/USN-1987-1
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.