Oracle Linux 4 : gnupg (ELSA-2006-0754)

This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.

Synopsis :

The remote Oracle Linux host is missing a security update.

Description :

From Red Hat Security Advisory 2006:0754 :

Updated GnuPG packages that fix two security issues are now available.

This update has been rated as having important security impact by the
Red Hat Security Response Team.

GnuPG is a utility for encrypting data and creating digital

Tavis Ormandy discovered a stack overwrite flaw in the way GnuPG
decrypts messages. An attacker could create carefully crafted message
that could cause GnuPG to execute arbitrary code if a victim attempts
to decrypt the message. (CVE-2006-6235)

A heap based buffer overflow flaw was found in the way GnuPG
constructs messages to be written to the terminal during an
interactive session. An attacker could create a carefully crafted
message which with user interaction could cause GnuPG to execute
arbitrary code with the permissions of the user running GnuPG.

All users of GnuPG are advised to upgrade to this updated package,
which contains a backported patch to correct these issues.

See also :

Solution :

Update the affected gnupg package.

Risk factor :

Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.7
Public Exploit Available : false

Family: Oracle Linux Local Security Checks

Nessus Plugin ID: 67429 ()

Bugtraq ID: 21306

CVE ID: CVE-2006-6169