ALSA-2020:4490

Source
https://errata.almalinux.org/8/ALSA-2020-4490.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2020:4490.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2020:4490
Related
  • CVE-2019-13050
Published
2020-11-03T12:09:29Z
Modified
2020-11-03T19:35:32Z
Summary
Moderate: gnupg2 security, bug fix, and enhancement update
Details

The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.

The following packages have been upgraded to a later upstream version: gnupg2 (2.2.20). (BZ#1663944)

Security Fix(es):

  • GnuPG: interaction between the sks-keyserver code and GnuPG allows for a Certificate Spamming Attack which leads to persistent DoS (CVE-2019-13050)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:8 / gnupg2

Package

Name
gnupg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.20-2.el8

AlmaLinux:8 / gnupg2-smime

Package

Name
gnupg2-smime

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.20-2.el8