gnupg key import memory corruption

Bug #1097188 reported by 4dro
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnupg (Ubuntu)
Fix Released
Undecided
Unassigned
gnupg2 (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Memory and key database corruption when importing with invalid keys.
See http://seclists.org/bugtraq/2012/Dec/151 and http://people.canonical.com/~ubuntu-security/cve/2012/CVE-2012-6085.html

A fix has been released by upstream.

CVE References

information type: Private Security → Public Security
Changed in gnupg2 (Ubuntu):
status: New → Confirmed
Changed in gnupg (Ubuntu):
status: New → Confirmed
Revision history for this message
4dro (kwadronaut) wrote :

Seems like only gnupg2 under Hardy is still affected, fix released for the other stable and supported flavors. The launchpad interface isn't helping me to pin it down to Hardy only, fix released for the stable/supported flavors.

Changed in gnupg (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Andy Whitcroft (apw) wrote :

As hardy is now fully Obsolete this is no longer valid for any supported series. I am closing out the gnupg2 task as well.

Changed in gnupg2 (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.