MGASA-2019-0348

Source
https://advisories.mageia.org/MGASA-2019-0348.html
Import Source
https://advisories.mageia.org/MGASA-2019-0348.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0348
Related
Published
2019-11-30T13:06:06Z
Modified
2019-11-30T12:40:07Z
Summary
Updated gnupg2 packages fix security vulnerability
Details

gnupg2 is updated to 2.2.18 and fix security vulnerability:

Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created with dsa1024 keys. The new option --allow-weak-key-signatues can be used to override the new and safer behaviour.

For other fixes in this update, see the gnupg-announce reference.

References
Credits

Affected packages

Mageia:7 / gnupg2

Package

Name
gnupg2
Purl
pkg:rpm/mageia/gnupg2?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.18-1.mga7

Ecosystem specific

{
    "section": "core"
}