Debian Security Advisory DSA 2967-1 (gnupg - security update)

Summary
Jean-René Reinhard, Olivier Levillain and Florian Maury reported that GnuPG, the GNU Privacy Guard, did not properly parse certain garbled compressed data packets. A remote attacker could use this flaw to mount a denial of service against GnuPG by triggering an infinite loop.
Solution
For the stable distribution (wheezy), this problem has been fixed in version 1.4.12-7+deb7u4. For the unstable distribution (sid), this problem has been fixed in version 1.4.16-1.2. We recommend that you upgrade your gnupg packages.
Insight
GnuPG is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC 4880.
Affected
gnupg on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References