Release date:
Updated on:
Affected Systems:
GnuPG <= 1.4.12
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57102
CVE (CAN) ID: CVE-2012-6085
GnuPG is a PGP encryption, decryption, and signature Tool Based on OpenPGP standards.
When importing public keys in versions earlier than GnuPG 1.4.13, there is a memory access corruption and public key database corruption vulnerability. Attackers can use a maliciously constructed public key to perform attacks and execute arbitrary code or destroy the database.
<* Source: KB Sriram (kbsriram@gmail.com)
Link: https://bugzilla.RedHat.com/show_bug.cgi? CVE-2012-6085
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GnuPG
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnupg.org/