- Issued:
- 2006-03-15
- Updated:
- 2006-03-15
RHSA-2006:0266 - Security Advisory
Synopsis
gnupg security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An updated GnuPG package that fixes signature verification flaws as well as
minor bugs is now available.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Description
GnuPG is a utility for encrypting data and creating digital signatures.
Tavis Ormandy discovered a bug in the way GnuPG verifies cryptographically
signed data with detached signatures. It is possible for an attacker to
construct a cryptographically signed message which could appear to come
from a third party. When a victim processes a GnuPG message with a
malformed detached signature, GnuPG ignores the malformed signature,
processes and outputs the signed data, and exits with status 0, just as it
would if the signature had been valid. In this case, GnuPG's exit status
would not indicate that no signature verification had taken place. This
issue would primarily be of concern when processing GnuPG results via an
automated script. The Common Vulnerabilities and Exposures project assigned
the name CVE-2006-0455 to this issue.
Tavis Ormandy also discovered a bug in the way GnuPG verifies
cryptographically signed data with inline signatures. It is possible for an
attacker to inject unsigned data into a signed message in such a way that
when a victim processes the message to recover the data, the unsigned data
is output along with the signed data, gaining the appearance of having been
signed. This issue is mitigated in the GnuPG shipped with Red Hat
Enterprise Linux as the --ignore-crc-error option must be passed to the gpg
executable for this attack to be successful. The Common Vulnerabilities and
Exposures project assigned the name CVE-2006-0049 to this issue.
Please note that neither of these issues affect the way RPM or up2date
verify RPM package files, nor is RPM vulnerable to either of these issues.
All users of GnuPG are advised to upgrade to this updated package, which
contains backported patches to correct these issues.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Affected Products
- Red Hat Enterprise Linux Server 4 x86_64
- Red Hat Enterprise Linux Server 4 ia64
- Red Hat Enterprise Linux Server 4 i386
- Red Hat Enterprise Linux Server 3 x86_64
- Red Hat Enterprise Linux Server 3 ia64
- Red Hat Enterprise Linux Server 3 i386
- Red Hat Enterprise Linux Server 2 ia64
- Red Hat Enterprise Linux Server 2 i386
- Red Hat Enterprise Linux Workstation 4 x86_64
- Red Hat Enterprise Linux Workstation 4 ia64
- Red Hat Enterprise Linux Workstation 4 i386
- Red Hat Enterprise Linux Workstation 3 x86_64
- Red Hat Enterprise Linux Workstation 3 ia64
- Red Hat Enterprise Linux Workstation 3 i386
- Red Hat Enterprise Linux Workstation 2 ia64
- Red Hat Enterprise Linux Workstation 2 i386
- Red Hat Enterprise Linux Desktop 4 x86_64
- Red Hat Enterprise Linux Desktop 4 i386
- Red Hat Enterprise Linux Desktop 3 x86_64
- Red Hat Enterprise Linux Desktop 3 i386
- Red Hat Enterprise Linux for IBM z Systems 4 s390x
- Red Hat Enterprise Linux for IBM z Systems 4 s390
- Red Hat Enterprise Linux for IBM z Systems 3 s390x
- Red Hat Enterprise Linux for IBM z Systems 3 s390
- Red Hat Enterprise Linux for Power, big endian 4 ppc
- Red Hat Enterprise Linux for Power, big endian 3 ppc
Fixes
- BZ - 167392 - initial gpg run doesn't create .gnupg/secring.gpg
- BZ - 179506 - RHEL3, gnupg-1.2.1-10, gpg: Creates corrupt files (probably 2GB problem)
- BZ - 183484 - CVE-2006-0455 gpg will quietly exit when attempting to verify a malformed message
- BZ - 184556 - CVE-2006-0049 Gnupg incorrect malformed message verification
References
(none)
Red Hat Enterprise Linux Server 4
SRPM | |
---|---|
x86_64 | |
gnupg-1.2.6-3.x86_64.rpm | SHA-256: 2aa0dcf75d0814ac7a6049bfeab9cc7b39ba6f6dab41693532984dc19909ba15 |
gnupg-1.2.6-3.x86_64.rpm | SHA-256: 2aa0dcf75d0814ac7a6049bfeab9cc7b39ba6f6dab41693532984dc19909ba15 |
ia64 | |
gnupg-1.2.6-3.ia64.rpm | SHA-256: 7268234f36dd489fa1f7ceaa6e49c8c866cc1660869a293d27bdd404e49097b0 |
gnupg-1.2.6-3.ia64.rpm | SHA-256: 7268234f36dd489fa1f7ceaa6e49c8c866cc1660869a293d27bdd404e49097b0 |
i386 | |
gnupg-1.2.6-3.i386.rpm | SHA-256: fd96959fe1f3bb45f594b1ae5b94700e230352336db7b4637ab5487795e348f6 |
gnupg-1.2.6-3.i386.rpm | SHA-256: fd96959fe1f3bb45f594b1ae5b94700e230352336db7b4637ab5487795e348f6 |
Red Hat Enterprise Linux Server 3
SRPM | |
---|---|
x86_64 | |
ia64 | |
i386 |
Red Hat Enterprise Linux Server 2
SRPM | |
---|---|
ia64 | |
i386 |
Red Hat Enterprise Linux Workstation 4
SRPM | |
---|---|
x86_64 | |
gnupg-1.2.6-3.x86_64.rpm | SHA-256: 2aa0dcf75d0814ac7a6049bfeab9cc7b39ba6f6dab41693532984dc19909ba15 |
ia64 | |
gnupg-1.2.6-3.ia64.rpm | SHA-256: 7268234f36dd489fa1f7ceaa6e49c8c866cc1660869a293d27bdd404e49097b0 |
i386 | |
gnupg-1.2.6-3.i386.rpm | SHA-256: fd96959fe1f3bb45f594b1ae5b94700e230352336db7b4637ab5487795e348f6 |
Red Hat Enterprise Linux Workstation 3
SRPM | |
---|---|
x86_64 | |
ia64 | |
i386 |
Red Hat Enterprise Linux Workstation 2
SRPM | |
---|---|
ia64 | |
i386 |
Red Hat Enterprise Linux Desktop 4
SRPM | |
---|---|
x86_64 | |
gnupg-1.2.6-3.x86_64.rpm | SHA-256: 2aa0dcf75d0814ac7a6049bfeab9cc7b39ba6f6dab41693532984dc19909ba15 |
i386 | |
gnupg-1.2.6-3.i386.rpm | SHA-256: fd96959fe1f3bb45f594b1ae5b94700e230352336db7b4637ab5487795e348f6 |
Red Hat Enterprise Linux Desktop 3
SRPM | |
---|---|
x86_64 | |
i386 |
Red Hat Enterprise Linux for IBM z Systems 4
SRPM | |
---|---|
s390x | |
gnupg-1.2.6-3.s390x.rpm | SHA-256: ec1a367397f62c9216d003c99cd1e40029ca2797842e9f680a514eb43a47b10a |
s390 | |
gnupg-1.2.6-3.s390.rpm | SHA-256: 915bd04789c8932198b9f9bb37ecca9f5bc729398c7f9a29a97b0566063f7284 |
Red Hat Enterprise Linux for IBM z Systems 3
SRPM | |
---|---|
s390x | |
s390 |
Red Hat Enterprise Linux for Power, big endian 4
SRPM | |
---|---|
ppc | |
gnupg-1.2.6-3.ppc.rpm | SHA-256: c3455f842b4995a8fca681eb2a01991136c1e776d5e71a61ec24843c32e5fe12 |
Red Hat Enterprise Linux for Power, big endian 3
SRPM | |
---|---|
ppc |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.