openSUSE 10 Security Update : gpg (gpg-2995)
Medium Nessus Plugin ID 27248
SynopsisThe remote openSUSE host is missing a security update.
DescriptionWhen printing a text stream with a GPG signature it was possible for an attacker to create a stream with 'unsigned text, signed text' where both unsigned and signed text would be shown without distinction which one was signed and which part wasn't.
This is tracked by the Mitre CVE ID CVE-2007-1263.
The update introduces a new option
--allow-multiple-messages to print out such messages in the future, by default it only prints and handles the first one.
SolutionUpdate the affected gpg package.