oval:org.mitre.oval:def:24793

Definition Id: oval:org.mitre.oval:def:24793
 
Oval ID: oval:org.mitre.oval:def:24793
Title: SUSE-SU-2013:1578-1 -- Security update for gpg
Description: This GnuPG LTSS roll-up update fixes two security issues: * CVE-2013-4351: GnuPG treated no-usage-permitted keys as all-usages-permitted. * CVE-2013-4402: An infinite recursion in the compressed packet parser was fixed. * CVE-2013-4242: GnuPG allowed local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload. * CVE-2012-6085: The read_block function in g10/import.c in GnuPG 1.4.x, when importing a key, allowed remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.
Family: unix Class: patch
Reference(s): SUSE-SU-2013:1578-1
CVE-2013-4351
CVE-2013-4402
CVE-2013-4242
CVE-2012-6085
Version: 3
Platform(s): SUSE Linux Enterprise Server 10
Product(s): gpg
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:1368
 
Oval ID: oval:org.mitre.oval:def:1368
Title: SUSE Linux Enterprise Server 10 is installed
Description: SUSE Linux Enterprise Server 10 is installed.
Family: unix Class: inventory
Reference(s): cpe:/o:novell:suse_linux:10::server
Version: 6
Platform(s): SUSE Linux Enterprise Server 10
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:24793