Release date:
Updated on:
Affected Systems:
Google Python-gnupg <0.3.6
Google Python-gnupg
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65548
CVE (CAN) ID: CVE-2014-1928
Python-gnupg is a GNU Privacy Protection Program Using Python APIs.
A remote command execution vulnerability exists in Python-gnupg 0.3.6 and earlier versions. Attackers can exploit this vulnerability to execute arbitrary commands in the context of the affected application.
<* Source: Matthew Daley
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Google
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://code.google.com/p/python-gnupg/