gpp_maybe Security update for gpg2
SUSE-SLE-Module-Basesystem-15-2018-1223


This update for gpg2 fixes the following security issue: - CVE-2018-12020: GnuPG mishandled the original filename during decryption and verification actions, which allowed remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option (bsc#1096745).

  • Release Date
    Jun 26 2018
  • References
    Bugzilla: 1096745
    CVEs: CVE-2018-12020
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15 ppc64le
  • Packages
    gpg2
    File encryption, decryption, signature creation and verification utility
    2.2.5-4.3.1 lock rpm lock src
    gpg2-lang
    Translations for package gpg2
    2.2.5-4.3.1 lock rpm
Basesystem Module 15 x86_64
  • Packages
    gpg2
    File encryption, decryption, signature creation and verification utility
    2.2.5-4.3.1 lock rpm lock src
    gpg2-lang
    Translations for package gpg2
    2.2.5-4.3.1 lock rpm
Basesystem Module 15 aarch64
  • Packages
    gpg2
    File encryption, decryption, signature creation and verification utility
    2.2.5-4.3.1 lock rpm lock src
    gpg2-lang
    Translations for package gpg2
    2.2.5-4.3.1 lock rpm
Basesystem Module 15 s390x
  • Packages
    gpg2
    File encryption, decryption, signature creation and verification utility
    2.2.5-4.3.1 lock rpm lock src
    gpg2-lang
    Translations for package gpg2
    2.2.5-4.3.1 lock rpm