SuSE9 Security Update : gpg (YOU Patch Number 11464)

medium Nessus Plugin ID 41120

Synopsis

The remote SuSE 9 host is missing a security-related patch.

Description

When printing a text stream with a GPG signature it was possible for an attacker to create a stream with 'unsigned text, signed text' where both unsigned and signed text would be shown without distinction which one was signed and which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option --allow-multiple-messages to print out such messages in the future, by default it only prints and handles the first one.

Solution

Apply YOU patch number 11464.

See Also

http://support.novell.com/security/cve/CVE-2007-1263.html

Plugin Details

Severity: Medium

ID: 41120

File Name: suse9_11464.nasl

Version: 1.7

Type: local

Agent: unix

Published: 9/24/2009

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 3/27/2007

Reference Information

CVE: CVE-2007-1263