Security update for gpg

SUSE Security Update: Security update for gpg
Announcement ID: SUSE-SU-2013:1061-1
Rating: low
References: #780943 #798465
Affected Products:
  • SUSE Linux Enterprise Server 10 SP4
  • SUSE Linux Enterprise Desktop 10 SP4

  • An update that solves one vulnerability and has one errata is now available.

    Description:


    This update for gpg provides the following fixes:

    * Set proper file permissions when en/de-crypting files
    (bnc#780943)
    * Fix an issue that could cause corruption of the
    public keys database. (CVE-2012-6085, bnc#798465)

    Security Issue reference:

    * CVE-2012-6085
    >

    Package List:

    • SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64):
    • gpg-1.4.2-23.21.1
    • gpg2-1.9.18-17.23.1
    • SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):
    • gpg-1.4.2-23.21.1
    • gpg2-1.9.18-17.23.1

    References:

    • http://support.novell.com/security/cve/CVE-2012-6085.html
    • https://bugzilla.novell.com/780943
    • https://bugzilla.novell.com/798465
    • http://download.suse.com/patch/finder/?keywords=3fc2b24dc90bda3b61202a7c4ffc0814
    • http://download.suse.com/patch/finder/?keywords=c63e1c0dad4c5e8848b14230545d1ec2