MGASA-2014-0276

Source
https://advisories.mageia.org/MGASA-2014-0276.html
Import Source
https://advisories.mageia.org/MGASA-2014-0276.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0276
Related
Published
2014-06-27T15:08:48Z
Modified
2014-06-27T15:08:05Z
Summary
Updated gnupg & gnupg2 packages fixes CVE-2014-4617
Details

Updated gnupg and gnupg2 packages fix security vulnerability:

GnuPG versions before 1.4.17 and 2.0.24 are vulnerable to a denial of service which can be caused by garbled compressed data packets which may put gpg into an infinite loop (CVE-2014-4617).

References
Credits

Affected packages

Mageia:4 / gnupg

Package

Name
gnupg
Purl
pkg:rpm/mageia/gnupg?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.16-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / gnupg2

Package

Name
gnupg2
Purl
pkg:rpm/mageia/gnupg2?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.22-3.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / gnupg

Package

Name
gnupg
Purl
pkg:rpm/mageia/gnupg?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.14-1.3.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / gnupg2

Package

Name
gnupg2
Purl
pkg:rpm/mageia/gnupg2?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.19-3.3.mga3

Ecosystem specific

{
    "section": "core"
}