SUSE-SU-2015:2170-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20152170-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2170-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:2170-1
Related
Published
2015-12-02T12:47:31Z
Modified
2015-12-02T12:47:31Z
Summary
Security update for gpg2
Details

This update for gpg2 fixes the following issues:

  • Fix cve-2015-1606 (bsc#918089)
    • Invalid memory read using a garbled keyring
    • 0001-Gpg-prevent-an-invalid-memory-read-using-a-garbled-k.patch
  • Fix cve-2015-1607 (bsc#918090)
    • Memcpy with overlapping ranges
    • 0001-Use-inline-functions-to-convert-buffer-data-to-scala.patch
References

Affected packages

SUSE:Linux Enterprise Desktop 11 SP3 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Desktop 11 SP4 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP3 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP3-TERADATA / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 11 SP3 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP4 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 11 SP4 / gpg2

Package

Name
gpg2
Purl
pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.9-25.33.41.2

Ecosystem specific

{
    "binaries": [
        {
            "gpg2-lang": "2.0.9-25.33.41.2",
            "gpg2": "2.0.9-25.33.41.2"
        }
    ]
}