GnuPG S/MIME Signing Unspecified Vulnerability
BID:13980
Info
GnuPG S/MIME Signing Unspecified Vulnerability
| Bugtraq ID: | 13980 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2005 12:00AM |
| Updated: | Jun 17 2005 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 GNU PG 1.9.14 |
| Not Vulnerable: |
GNU PG 1.9.17 GNU PG 1.9.16 GNU PG 1.9.15 |
Discussion
GnuPG S/MIME Signing Unspecified Vulnerability
GnuPG is affected by an unspecified vulnerability related to S/MIME signing. The cause and impact of this issue is currently unknown.
Due to a lack of details, it cannot be confirmed whether this issue poses a security threat or results in an adverse affect on the functionality of the application. It is conjectured that this issue is remote in nature.
This BID will be updated when more details are available.
GnuPG is affected by an unspecified vulnerability related to S/MIME signing. The cause and impact of this issue is currently unknown.
Due to a lack of details, it cannot be confirmed whether this issue poses a security threat or results in an adverse affect on the functionality of the application. It is conjectured that this issue is remote in nature.
This BID will be updated when more details are available.
Exploit / POC
GnuPG S/MIME Signing Unspecified Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GnuPG S/MIME Signing Unspecified Vulnerability
Solution:
The vendor has released a patch for this issue.
SUSE has released advisory SUSE-SR:2005:016 to address this issue. Please see the referenced advisory for more information.
GNU PG 1.9.14
Solution:
The vendor has released a patch for this issue.
SUSE has released advisory SUSE-SR:2005:016 to address this issue. Please see the referenced advisory for more information.
GNU PG 1.9.14
-
GNU gnupg-1.9.17.tar.bz2
ftp://ftp.gnupg.org/gcrypt/alpha/gnupg/gnupg-1.9.17.tar.bz2
References
GnuPG S/MIME Signing Unspecified Vulnerability
References:
References:
- Diff for /gnupg/common/Attic/asshelp.c between version 1.1.2.4 and 1.1.2.5 (GnuPG Development)