CVE-2006-0455

Publication date 15 February 2006

Last updated 24 July 2024


Ubuntu priority

gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".

Status

Package Ubuntu Release Status
gnupg 7.04 feisty
Fixed 1.4.6-1ubuntu2
6.10 edgy
Fixed 1.4.3-2ubuntu3.3
6.06 LTS dapper
Fixed 1.4.2.2-1ubuntu2.5

References

Related Ubuntu Security Notices (USN)

    • USN-252-1
    • gnupg vulnerability
    • 18 February 2006

Other references