Jump to content

Advisories MDKSA-2007:059: Updated gnupg packages provide enhanced forgery detection


paul
 Share

Recommended Posts

GnuPG prior to 1.4.7 and GPGME prior to 1.1.4, when run from the

command

line, did not visually distinguish signed and unsigned portions of

OpenPGP messages with multiple components. This could allow a remote

attacker to forge the contents of an email message without detection.

 

GnuPG 1.4.7 is being provided with this update and GPGME has been

patched on Mandriva 2007.0 to provide better visual notification on

these types of forgeries.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...