Wind River Support Network

HomeDefectsLIN6-5051
Fixed

LIN6-5051 : Security Advisory - gnupg - CVE-2013-4351

Created: Oct 16, 2013    Updated: Dec 3, 2018
Resolved Date: Dec 19, 2013
Previous ID: LIN3-9295
Found In Version: 6.0
Fix Version: 6.0.0.2
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4351

Workaround

Unknown

Steps to Reproduce

Unknown

Other Downloads


Live chat
Online