CVE-2006-0049
Publication date 13 March 2006
Last updated 24 July 2024
Ubuntu priority
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnupg | 7.04 feisty |
Fixed 1.4.6-1ubuntu2
|
6.10 edgy |
Fixed 1.4.3-2ubuntu3.3
|
|
6.06 LTS dapper |
Fixed 1.4.2.2-1ubuntu2.5
|