Security Advisory Updated gnupg packages now available

Advisory: RHSA-2000:131-02
Type: Security Advisory
Severity: N/A
Issued on: 2000-12-19
Last updated on: 2000-12-19
Affected Products: Red Hat Linux 6.2
Red Hat Linux 7.0
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-0071
CVE-2001-0072

Details

Updated gnupg packages are now available for Red Hat Linux 6.x and 7.

When importing keys from public key servers, GnuPG will import private keys
(also known as secret keys) in addition to public keys. If this happens,
the user's web of trust becomes corrupted. Additionally, when used to check
detached signatures, if the data file being checked contained clearsigned
data, GnuPG would not warn the user if the detached signature was
incorrect.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

Updated packages

Red Hat Linux 6.2

alpha:
ftp://updates.redhat.com/6.2/alpha/gnupg-1.0.4-8.6.x.alpha.rpm
Missing file
    aae767039effc37d4a929428e0d19543
 
i386:
ftp://updates.redhat.com/6.2/i386/gnupg-1.0.4-8.6.x.i386.rpm
Missing file
    887b2d7d888fb8ee84c81cee7832384e
 
sparc:
ftp://updates.redhat.com/6.2/sparc/gnupg-1.0.4-8.6.x.sparc.rpm
Missing file
    d7a3124166bc5c35cd3ca2dec36c97e0
 
Red Hat Linux 7.0

alpha:
ftp://updates.redhat.com/7.0/alpha/gnupg-1.0.4-9.alpha.rpm
Missing file
    1f476ae8f5453655a4a61174de187d15
 
i386:
ftp://updates.redhat.com/7.0/i386/gnupg-1.0.4-9.i386.rpm
Missing file
    88ac7d34da177b6c469e0f2a0f6117e6
 

References


Keywords

detached-signature


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/