SuSE9 Security Update : gpg (YOU Patch Number 11464)
Medium Nessus Plugin ID 41120
SynopsisThe remote SuSE 9 host is missing a security-related patch.
DescriptionWhen printing a text stream with a GPG signature it was possible for an attacker to create a stream with 'unsigned text, signed text' where both unsigned and signed text would be shown without distinction which one was signed and which part wasn't.
This is tracked by the Mitre CVE ID CVE-2007-1263.
The update introduces a new option --allow-multiple-messages to print out such messages in the future, by default it only prints and handles the first one.
SolutionApply YOU patch number 11464.