Jump to content

Advisories MDVSA-2010:143: gnupg2


paul
 Share

Recommended Posts

A vulnerability has been discovered and corrected in gnupg2:

 

Importing a certificate with more than 98 Subject Alternate Names

via GPGSM's import command or implicitly while verifying a signature

causes GPGSM to reallocate an array with the names. The bug is that

the reallocation code misses assigning the reallocated array to the old

array variable and thus the old and freed array will be used. Usually

this leads to a segv (CVE-2010-2547).

 

Packages for 2008.0 and 2009.0 are provided as of the Extended

Maintenance Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...