Secunia Logo
Netsikker nu! 2008
 
Debian update for gnupg
Secunia Advisory: SA10715
Release Date: 2004-01-27
Last Update: 2004-02-16
Popularity: 6,453 views

Critical:
Moderately critical
Impact: Spoofing
Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0971


Description:
Debian has issued updated packages for gnupg. These fix a vulnerability, which exposes the private key when using El-Gamal type 20 keys.

For more information:
SA10304

Solution:
Apply updated packages.

Debian GNU/Linux 3.0 alias woody

Source archives:

http://security.debian.org/pool/updates/main/g/gnupg/gnupg_1.0.6-4woody3.dsc
Size/MD5 checksum: 577 f5a742233c584754c479daf7dfe58a9e
http://security.debian.org/pool/updates/main/g/gnupg/gnupg_1.0.6-4woody3.diff.gz
Size/MD5 checksum: 5262 1ecf9f459e0b05c31128adac05ef2fe4
http://security.debian.org/pool/updates/main/g/gnupg/gnupg_1.0.6.orig.tar.gz
Size/MD5 checksum: 1941676 7c319a9e5e70ad9bc3bf0d7b5008a508

Alpha architecture:

http://security.debian.org/pool/updat...g/gnupg/gnupg_1.0.6-4woody3_alpha.deb
Size/MD5 checksum: 1150082 724d4fcb6f2ff0969b5ceba82e8aabe5

ARM architecture:

http://security.debian.org/pool/updates/main/g/gnupg/gnupg_1.0.6-4woody3_arm.deb
Size/MD5 checksum: 986748 8efdbc409f140c1aaefadb97646944d6

Intel IA-32 architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_i386.deb
Size/MD5 checksum: 966408 50e5e44b2efa34d7c7d3a8fd630dc96a

Intel IA-64 architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_ia64.deb
Size/MD5 checksum: 1271406 4c5e77defc13bf4bae3d11431257e6a3

HP Precision architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_hppa.deb
Size/MD5 checksum: 1058822 02516b6984cf695ef31c970980d36864

Motorola 680x0 architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_m68k.deb
Size/MD5 checksum: 942188 ed7d9d16820608b3172be64f6b470b97

Big endian MIPS architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_mips.deb
Size/MD5 checksum: 1035630 9b25dd3f06580549bfa93ee429605d0e

Little endian MIPS architecture:

http://security.debian.org/pool/updat.../gnupg/gnupg_1.0.6-4woody3_mipsel.deb
Size/MD5 checksum: 1035864 740243a767cc1ff53f116d0e97aa66a7

PowerPC architecture:

http://security.debian.org/pool/updat...gnupg/gnupg_1.0.6-4woody3_powerpc.deb
Size/MD5 checksum: 1009152 678b2fc28d01eac452d96f925d2d40b2

IBM S/390 architecture:

http://security.debian.org/pool/updat.../g/gnupg/gnupg_1.0.6-4woody3_s390.deb
Size/MD5 checksum: 1001666 c5a70add4dfa1cb3828d9892513d3c15

Sun Sparc architecture:

http://security.debian.org/pool/updat...g/gnupg/gnupg_1.0.6-4woody3_sparc.deb
Size/MD5 checksum: 1003634 32490333505f1804e9fcf4a786fbc293

Debian GNU/Linux unstable alias sid

This will be fixed in 1.2.4-1.

Changelog:
2004-02-16: Debian has issued new packages.

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2004/msg00024.html

Other References:
SA10304:
http://secunia.com/advisories/10304/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. My PHP Indexer "d" File Disclosure Vulnerability // 76 views
2. NewLife Blogger "nlb3" SQL Injection Vulnerability // 53 views
3. ArticleBeach Script "page" File Inclusion Vulnerability // 50 views
4. Subdreamer Light Global Variables SQL Injection Vulnerability // 46 views
5. WinFTP "PASV" Denial of Service Vulnerability // 45 views
6. Joomla Ignite Gallery Component "gallery" SQL Injection // 42 views
7. Ayco Okul "linkid" SQL Injection Vulnerability // 42 views
8. Real Estates Classifieds "cat" SQL Injection Vulnerability // 37 views
9. ScriptsEz Mini Hosting Panel "dir" File Disclosure // 36 views
10. Joomla Mad4Joomla Mailforms Component "jid" SQL Injection // 31 views