Wind River Support Network

HomeDefectsLIN5-15421
Fixed

LIN5-15421 : Security Advisory - gnupg - CVE-2013-4351

Created: Oct 16, 2013    Updated: Dec 19, 2017
Resolved Date: Dec 17, 2013
Previous ID: LIN3-9286
Found In Version: 5.0
Fix Version: 5.0.1.11
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4351

Workaround

Unknown

Steps to Reproduce

Unknown

Other Downloads


Live chat
Online