FS#58931 - [gnupg] [Security] content spoofing (CVE-2018-12020)
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Friday, 08 June 2018, 14:41 GMT
Last edited by Gaetan Bisson (vesath) - Friday, 08 June 2018, 17:38 GMT
Opened by Remi Gacogne (rgacogne) - Friday, 08 June 2018, 14:41 GMT
Last edited by Gaetan Bisson (vesath) - Friday, 08 June 2018, 17:38 GMT
|
Details
Summary
======= The package gnupg is vulnerable to content spoofing via CVE-2018-12020. Guidance ======== We should upgrade to 2.2.8, this is just a reminder. References ========== https://security.archlinux.org/AVG-713 https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html https://dev.gnupg.org/T4012 https://dev.gnupg.org/rG210e402acd3e284b32db1901e43bf1470e659e49 |
This task depends upon
Closed by Gaetan Bisson (vesath)
Friday, 08 June 2018, 17:38 GMT
Reason for closing: Fixed
Additional comments about closing: gnupg-2.2.8-1 in [testing]
Friday, 08 June 2018, 17:38 GMT
Reason for closing: Fixed
Additional comments about closing: gnupg-2.2.8-1 in [testing]