Debian Security Update DSA-5174 gnupg2 - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,969
Reaction score
80
Credits
-1,257
Demi Marie Obenour discovered a flaw in GnuPG, allowing for signature spoofing via arbitrary injection into the status line. An attacker who controls the secret part of any signing-capable key or subkey in the victim's keyring, can take advantage of this flaw to provide a correctly-formed signature that some software, including gpgme, will accept to have validity and signer fingerprint chosen from the attacker.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top