Summary
The remote host is missing updates announced in
advisory GLSA 200312-05.
Solution
All users who have created ElGamal signing keys should immediately revoke them. In addition, all Gentoo Linux machines with gnupg installed should be updated to use gnupg-1.2.3-r5 or higher:
# emerge sync
# emerge -pv '>=app-crypt/gnupg-1.2.3-r5'
# emerge '>=app-crypt/gnupg-1.2.3-r5'
# emerge clean
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200312-05 http://bugs.gentoo.org/show_bug.cgi?id=34504
http://marc.theaimsgroup.com/?l=gnupg-announce&m=106992378510843&q=raw http://www.s-quadra.com/advisories/Adv-20031203.txt
Insight
A bug in GnuPG allows ElGamal signing keys to be compromised, and a format string bug in the gpgkeys_hkp utility may allow arbitrary code execution.
Severity
Classification
-
CVE CVE-2003-0971 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities