- Status Closed
- Percent Complete
- Task Type Security Issue
- Category Any
-
Assigned To
Emulatorman - Operating System All
- Severity High
- Priority Very High
- Reported Version Any
- Due in Version Starfix
-
Due Date
Undecided
- Votes
- Private
Attached to Project: Packages
Opened by bugmen0t - 21/06/2018
Last edited by Emulatorman - 23/06/2018
Opened by bugmen0t - 21/06/2018
Last edited by Emulatorman - 23/06/2018
FS#1027 - [gnupg] CVE-2018-12020
https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html
We are pleased to announce the availability of a new GnuPG release:
version 2.2.8. This version fixes a critical security bug and comes
with some other minor changes.
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
https://security-tracker.debian.org/tracker/CVE-2018-12020
Debian pushed a new patch (see attachment) to solve this issue in its stable version of GnuPG (2.1.18-8~deb9u2) [0] , therefore upgrade Debian patches in our package is enough to fix this issue.
I've pushed a new package called gnupg-stable that replaces gnupg, it contains the required patches to solve the issue. So, i'm closing this report, thank you for the report!