Ubuntu Security Notice USN-264-1
4th April, 2006
gnupg vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 5.10
- Ubuntu 5.04
- Ubuntu 4.10
Details
Tavis Ormandy discovered a flaw in gnupg's signature verification. In
some cases, certain invalid signature formats could cause gpg to
report a 'good signature' result for auxiliary unsigned data which was
prepended or appended to the checked message part.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 5.10:
- gnupg
- Ubuntu 5.04:
- gnupg
- Ubuntu 4.10:
- gnupg
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
None