openSUSE 10 Security Update : gpg (gpg-2995)

Medium Nessus Plugin ID 27248


The remote openSUSE host is missing a security update.


When printing a text stream with a GPG signature it was possible for an attacker to create a stream with 'unsigned text, signed text' where both unsigned and signed text would be shown without distinction which one was signed and which part wasn't.

This is tracked by the Mitre CVE ID CVE-2007-1263.

The update introduces a new option

--allow-multiple-messages to print out such messages in the future, by default it only prints and handles the first one.


Update the affected gpg package.

Plugin Details

Severity: Medium

ID: 27248

File Name: suse_gpg-2995.nasl

Version: $Revision: 1.8 $

Type: local

Agent: unix

Published: 2007/10/17

Modified: 2014/06/13

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:gpg, cpe:/o:novell:opensuse:10.1, cpe:/o:novell:opensuse:10.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2007/03/23

Reference Information

CVE: CVE-2007-1263