gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-978-1 | New GnuPG packages fix invalid success return |
EUVD |
EUVD-2006-0462 | gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify". |
Ubuntu USN |
USN-252-1 | gnupg vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T16:34:14.838Z
Reserved: 2006-01-27T00:00:00
Link: CVE-2006-0455
No data.
Status : Deferred
Published: 2006-02-15T22:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0455
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN