Summary
The remote host is missing an update to gnupg
announced via advisory DSA 1266-1.
Gerardo Richarte discovered that GnuPG, a free PGP replacement, provides insufficient user feedback if an OpenPGP message contains both unsigned and signed portions. Inserting text segments into an otherwise signed message could be exploited to forge the content of signed messages.
This update prevents such attacks
the old behaviour can still be
activated by passing the --allow-multiple-messages option.
Solution
For the stable distribution (sarge) these problems have been fixed in version 1.4.1-1.sarge7.
For the upcoming stable distribution (etch) these problems have been fixed in version 1.4.6-2.
For the unstable distribution (sid) these problems have been fixed in version 1.4.6-2.
We recommend that you upgrade your gnupg packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201266-1
Severity
Classification
-
CVE CVE-2007-1263 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
Related Vulnerabilities