This script is Copyright (C) 2006-2015 Tenable Network Security, Inc.
The remote Red Hat host is missing a security update.
Updated GnuPG packages that fix two security issues are now available.
This update has been rated as having important security impact by the
Red Hat Security Response Team.
GnuPG is a utility for encrypting data and creating digital
Tavis Ormandy discovered a stack overwrite flaw in the way GnuPG
decrypts messages. An attacker could create carefully crafted message
that could cause GnuPG to execute arbitrary code if a victim attempts
to decrypt the message. (CVE-2006-6235)
A heap based buffer overflow flaw was found in the way GnuPG
constructs messages to be written to the terminal during an
interactive session. An attacker could create a carefully crafted
message which with user interaction could cause GnuPG to execute
arbitrary code with the permissions of the user running GnuPG.
All users of GnuPG are advised to upgrade to this updated package,
which contains a backported patch to correct these issues.
See also :
Update the affected gnupg package.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.7
Public Exploit Available : false
Family: Red Hat Local Security Checks
Nessus Plugin ID: 23798 ()
Bugtraq ID: 2130621462
CVE ID: CVE-2006-6169CVE-2006-6235
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.