Debian Security Advisory

DSA-2967-1 gnupg -- security update

Date Reported:
25 Jun 2014
Affected Packages:
gnupg
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 752497.
In Mitre's CVE dictionary: CVE-2014-4617.
More information:

Jean-René Reinhard, Olivier Levillain and Florian Maury reported that GnuPG, the GNU Privacy Guard, did not properly parse certain garbled compressed data packets. A remote attacker could use this flaw to mount a denial of service against GnuPG by triggering an infinite loop.

For the stable distribution (wheezy), this problem has been fixed in version 1.4.12-7+deb7u4.

For the unstable distribution (sid), this problem has been fixed in version 1.4.16-1.2.

We recommend that you upgrade your gnupg packages.