CVE-2006-0049

gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U
http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html Patch Vendor Advisory
http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html
http://secunia.com/advisories/19173 Patch Vendor Advisory
http://secunia.com/advisories/19197
http://secunia.com/advisories/19203
http://secunia.com/advisories/19231
http://secunia.com/advisories/19232
http://secunia.com/advisories/19234
http://secunia.com/advisories/19244
http://secunia.com/advisories/19249
http://secunia.com/advisories/19287
http://secunia.com/advisories/19532
http://securityreason.com/securityalert/450
http://securityreason.com/securityalert/568
http://securitytracker.com/id?1015749 Patch
http://www.debian.org/security/2006/dsa-993 Patch Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:055
http://www.osvdb.org/23790 Patch
http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html
http://www.redhat.com/support/errata/RHSA-2006-0266.html
http://www.securityfocus.com/archive/1/427324/100/0/threaded
http://www.securityfocus.com/archive/1/433931/100/0/threaded
http://www.securityfocus.com/bid/17058 Patch
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477
http://www.trustix.org/errata/2006/0014
http://www.vupen.com/english/advisories/2006/0915
https://exchange.xforce.ibmcloud.com/vulnerabilities/25184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063
https://usn.ubuntu.com/264-1/
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U
http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html Patch Vendor Advisory
http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html
http://secunia.com/advisories/19173 Patch Vendor Advisory
http://secunia.com/advisories/19197
http://secunia.com/advisories/19203
http://secunia.com/advisories/19231
http://secunia.com/advisories/19232
http://secunia.com/advisories/19234
http://secunia.com/advisories/19244
http://secunia.com/advisories/19249
http://secunia.com/advisories/19287
http://secunia.com/advisories/19532
http://securityreason.com/securityalert/450
http://securityreason.com/securityalert/568
http://securitytracker.com/id?1015749 Patch
http://www.debian.org/security/2006/dsa-993 Patch Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:055
http://www.osvdb.org/23790 Patch
http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html
http://www.redhat.com/support/errata/RHSA-2006-0266.html
http://www.securityfocus.com/archive/1/427324/100/0/threaded
http://www.securityfocus.com/archive/1/433931/100/0/threaded
http://www.securityfocus.com/bid/17058 Patch
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477
http://www.trustix.org/errata/2006/0014
http://www.vupen.com/english/advisories/2006/0915
https://exchange.xforce.ibmcloud.com/vulnerabilities/25184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063
https://usn.ubuntu.com/264-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:privacy_guard:1.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.3b:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.2:rc1:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:05

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U - () ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U -
References () http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html - Patch, Vendor Advisory () http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html - Patch, Vendor Advisory
References () http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html - () http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html -
References () http://secunia.com/advisories/19173 - Patch, Vendor Advisory () http://secunia.com/advisories/19173 - Patch, Vendor Advisory
References () http://secunia.com/advisories/19197 - () http://secunia.com/advisories/19197 -
References () http://secunia.com/advisories/19203 - () http://secunia.com/advisories/19203 -
References () http://secunia.com/advisories/19231 - () http://secunia.com/advisories/19231 -
References () http://secunia.com/advisories/19232 - () http://secunia.com/advisories/19232 -
References () http://secunia.com/advisories/19234 - () http://secunia.com/advisories/19234 -
References () http://secunia.com/advisories/19244 - () http://secunia.com/advisories/19244 -
References () http://secunia.com/advisories/19249 - () http://secunia.com/advisories/19249 -
References () http://secunia.com/advisories/19287 - () http://secunia.com/advisories/19287 -
References () http://secunia.com/advisories/19532 - () http://secunia.com/advisories/19532 -
References () http://securityreason.com/securityalert/450 - () http://securityreason.com/securityalert/450 -
References () http://securityreason.com/securityalert/568 - () http://securityreason.com/securityalert/568 -
References () http://securitytracker.com/id?1015749 - Patch () http://securitytracker.com/id?1015749 - Patch
References () http://www.debian.org/security/2006/dsa-993 - Patch, Vendor Advisory () http://www.debian.org/security/2006/dsa-993 - Patch, Vendor Advisory
References () http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml - Patch, Vendor Advisory () http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml - Patch, Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:055 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:055 -
References () http://www.osvdb.org/23790 - Patch () http://www.osvdb.org/23790 - Patch
References () http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html - () http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0266.html - () http://www.redhat.com/support/errata/RHSA-2006-0266.html -
References () http://www.securityfocus.com/archive/1/427324/100/0/threaded - () http://www.securityfocus.com/archive/1/427324/100/0/threaded -
References () http://www.securityfocus.com/archive/1/433931/100/0/threaded - () http://www.securityfocus.com/archive/1/433931/100/0/threaded -
References () http://www.securityfocus.com/bid/17058 - Patch () http://www.securityfocus.com/bid/17058 - Patch
References () http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477 - () http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477 -
References () http://www.trustix.org/errata/2006/0014 - () http://www.trustix.org/errata/2006/0014 -
References () http://www.vupen.com/english/advisories/2006/0915 - () http://www.vupen.com/english/advisories/2006/0915 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25184 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25184 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063 -
References () https://usn.ubuntu.com/264-1/ - () https://usn.ubuntu.com/264-1/ -

Information

Published : 2006-03-13 21:06

Updated : 2024-11-21 00:05


NVD link : CVE-2006-0049

Mitre link : CVE-2006-0049

CVE.ORG link : CVE-2006-0049


JSON object : View

Products Affected

gnu

  • privacy_guard