|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
rPath Information for VU#427009
| Date Notified: | |
| Date Updated: | |
| Statement Date: | |
| Status Summary: | Vulnerable |
Vendor Statement
rPath Security Advisory: 2006-0227-1
Published: 2006-12-06
Products: rPath Linux 1
Rating: Severe
Exposure Level Classification:
Indirect Deterministic Privilege Escalation
Updated Versions:
gnupg=/conary.rpath.com@rpl:devel//1/1.4.6-0.1-
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6235
https://issues.rpath.com/browse/RPL-835
Description:
Previous versions of the gnupg package will execute attacker-provided
code found in intentionally malformed OpenPGP packets. This allows an
attacker to run arbitrary code as the user invoking gpg on the file
that contains the malformed packets.
Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumThere are no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |