Information on source package gnupg

Available versions

wheezy (security)1.4.12-7+deb7u9
jessie (security)1.4.18-7+deb8u4

Open issues

CVE-2015-1607vulnerable (no DSA)fixedmemcpy with overlapping ranges, resulting from incorrect bitwise left shifts

Open unimportant issues

CVE-2018-6829vulnerablevulnerablecipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt ...

Resolved issues

TEMP-0107374-DF37E7gnupg: inproper flagging of signatures as being local
CVE-2017-7526Use of left-to-right sliding window method allows full RSA key recovery
CVE-2016-6313The mixing functions in the random number generator in Libgcrypt ...
CVE-2015-1606use after free resulting from failure to skip invalid packets
CVE-2015-0837data-dependent timing variations in modular exponentiation
CVE-2014-5270Libgcrypt before 1.5.4, as used in GnuPG and other products, does not ...
CVE-2014-4617The do_uncompress function in g10/compress.c in GnuPG 1.x before ...
CVE-2014-3591sidechannel attack on Elgamal
CVE-2013-4576GnuPG 1.x before 1.4.16 generates RSA keys using sequences of ...
CVE-2013-4402The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x ...
CVE-2013-4351GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all ...
CVE-2013-4242GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x ...
CVE-2012-6085The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 ...
CVE-2008-1530GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial ...
CVE-2007-1263GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the ...
CVE-2006-6235A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x ...
CVE-2006-6169Heap-based buffer overflow in the ask_outfile_name function in ...
CVE-2006-3746Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote ...
CVE-2006-3082parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, ...
CVE-2006-0455gpgv in GnuPG before, when using unattended signature ...
CVE-2006-0049gpg in GnuPG before does not properly verify non-detached ...
CVE-2005-0366The integrity check feature in OpenPGP, when handling a message that ...
CVE-2003-0971GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal ...
CVE-2003-0255The key validation code in GnuPG before 1.2.2 does not properly ...

Security announcements

