[Secure-testing-team] Bug#725433: CVE-2013-4402: infinite recursion in the compressed packet parser

Eric Dorland eric at debian.org
Sat Oct 5 19:51:58 UTC 2013


Package: gnupg2
Version: 2.0.21-2
Severity: normal
Tags: security

Fixed in 2.0.22.

-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.10-3-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages gnupg2 depends on:
ii  dpkg             1.17.1
ii  gnupg-agent      2.0.21-2
ii  install-info     5.2.0.dfsg.1-1
ii  libassuan0       2.1.1-1
ii  libbz2-1.0       1.0.6-5
ii  libc6            2.17-93
ii  libcurl3-gnutls  7.32.0-1
ii  libgcrypt11      1.5.3-2
ii  libgpg-error0    1.12-0.2
ii  libksba8         1.3.0-2
ii  libreadline6     6.2+dfsg-0.1
ii  zlib1g           1:1.2.8.dfsg-1

Versions of packages gnupg2 recommends:
ii  libldap-2.4-2  2.4.31-1+nmu2+b1

Versions of packages gnupg2 suggests:
pn  gnupg-doc   <none>
pn  xloadimage  <none>

-- no debconf information



More information about the Secure-testing-team mailing list