Debian Security Advisory
DSA-2967-1 gnupg -- security update
- Date Reported:
- 25 Jun 2014
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 752497.
In Mitre's CVE dictionary: CVE-2014-4617.
- More information:
Jean-René Reinhard, Olivier Levillain and Florian Maury reported that GnuPG, the GNU Privacy Guard, did not properly parse certain garbled compressed data packets. A remote attacker could use this flaw to mount a denial of service against GnuPG by triggering an infinite loop.
For the stable distribution (wheezy), this problem has been fixed in version 1.4.12-7+deb7u4.
For the unstable distribution (sid), this problem has been fixed in version 1.4.16-1.2.
We recommend that you upgrade your gnupg packages.