gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-03-13 13:06
Updated : 2018-10-19 08:42
NVD link : CVE-2006-0049
Mitre link : CVE-2006-0049
JSON object : View
CWE
Products Affected
gnu
- privacy_guard