Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52975
Categoría:Turbolinux Local Security Tests
Título:Turbolinux TLSA-2003-68 (gnupg)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to gnupg
announced via advisory TLSA-2003-68.

GnuPG is a complete and free replacement for PGP. Because it does not
use IDEA or RSA it can be used without any restrictions. GnuPG is in
compliance with the OpenPGP specification (RFC2440).
Phong Nguyen identified a severe bug in the way GnuPG creates and uses
ElGamal keys for signing. This is a significant security failure
which can lead to a compromise of almost all ElGamal keys used for
signing. Note that this is a real world vulnerability which will
reveal your private key within a few seconds.

This vulnerability may allow attackers to determine the private key from a signature.

Solution: Please use the turbopkg (zabom) tool to apply the update.
https://secure1.securityspace.com/smysecure/catid.html?in=TLSA-2003-68

Risk factor : Medium

CVSS Score:
5.0

Referencia Cruzada: BugTraq ID: 9115
Common Vulnerability Exposure (CVE) ID: CVE-2003-0971
http://www.securityfocus.com/bid/9115
Bugtraq: 20031127 GnuPG's ElGamal signing keys compromised (Google Search)
http://marc.info/?l=bugtraq&m=106995769213221&w=2
CERT/CC vulnerability note: VU#940388
http://www.kb.cert.org/vuls/id/940388
Conectiva Linux advisory: CLA-2003:798
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000798
Debian Security Information: DSA-429 (Google Search)
http://www.debian.org/security/2004/dsa-429
http://www.mandriva.com/security/advisories?name=MDKSA-2003:109
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982
http://www.redhat.com/support/errata/RHSA-2003-390.html
http://www.redhat.com/support/errata/RHSA-2003-395.html
http://secunia.com/advisories/10304
http://secunia.com/advisories/10349
http://secunia.com/advisories/10399
http://secunia.com/advisories/10400
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
SuSE Security Announcement: SuSE-SA:2003:048 (Google Search)
http://www.novell.com/linux/security/advisories/2003_048_gpg.html
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.