Mandrake Linux Security Advisory : gnupg (MDKSA-2007:059)
High Nessus Plugin ID 24809
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionGnuPG prior to 1.4.7 and GPGME prior to 1.1.4, when run from the command line, did not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components. This could allow a remote attacker to forge the contents of an email message without detection.
GnuPG 1.4.7 is being provided with this update and GPGME has been patched on Mandriva 2007.0 to provide better visual notification on these types of forgeries.
SolutionUpdate the affected packages.