Summary
Multiple vulnerabilities were discovered in the Python wrapper for the Gnu Privacy Guard (GPG). Insufficient sanitising could lead to the execution of arbitrary shell commands.
Solution
For the stable distribution (wheezy), these problems have been fixed in version 0.3.6-1~deb7u1.
For the testing distribution (jessie), these problems have been fixed in version 0.3.6-1.
For the unstable distribution (sid), these problems have been fixed in version 0.3.6-1.
We recommend that you upgrade your python-gnupg packages.
Insight
Python-GnuPG allows easy and well-documented access to basic GnuPG functionality such as generating and managing keys, encrypting and decrypting data, signing and verifying messages.
Affected
python-gnupg on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-7323, CVE-2014-1927, CVE-2014-1928, CVE-2014-1929 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities