Debian Security Advisory

DSA-2946-1 python-gnupg -- security update

Date Reported:
04 Jun 2014
Affected Packages:
python-gnupg
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-7323, CVE-2014-1927, CVE-2014-1928, CVE-2014-1929.
More information:

Multiple vulnerabilities were discovered in the Python wrapper for the Gnu Privacy Guard (GPG). Insufficient sanitising could lead to the execution of arbitrary shell commands.

For the stable distribution (wheezy), these problems have been fixed in version 0.3.6-1~deb7u1.

For the testing distribution (jessie), these problems have been fixed in version 0.3.6-1.

For the unstable distribution (sid), these problems have been fixed in version 0.3.6-1.

We recommend that you upgrade your python-gnupg packages.