SuSE 10 Security Update : gpg (ZYPP Patch Number 2994)

medium Nessus Plugin ID 29450

Synopsis

The remote SuSE 10 host is missing a security-related patch.

Description

When printing a text stream with a GPG signature it was possible for an attacker to create a stream with 'unsigned text, signed text' where both unsigned and signed text would be shown without distinction which one was signed and which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option

-allow-multiple-messages to print out such messages in the future, by default it only prints and handles the first one.

Solution

Apply ZYPP patch number 2994.

See Also

http://support.novell.com/security/cve/CVE-2007-1263.html

Plugin Details

Severity: Medium

ID: 29450

File Name: suse_gpg-2994.nasl

Version: 1.13

Type: local

Agent: unix

Published: 12/13/2007

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 3/23/2007

Reference Information

CVE: CVE-2007-1263