Mandrake Linux Security Advisory : gnupg (MDKSA-2003:061)
Critical Nessus Plugin ID 14044
SynopsisThe remote Mandrake Linux host is missing a security update.
DescriptionA bug was discovered in GnuPG versions 1.2.1 and earlier. When gpg evaluates trust values for different UIDs assigned to a key, it would incorrectly associate the trust value of the UID with the highest trust value with every other UID assigned to that key. This prevents a warning message from being given when attempting to encrypt to an invalid UID, but due to the bug, is accepted as valid.
Patches have been applied for version 1.0.7 and all users are encouraged to upgrade.
SolutionUpdate the affected gnupg package.