SUSE-SU-2015:2170-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2170-1
SUSE-SU-2015:2170-1
Summary: Security update for gpg2
Details: This update for gpg2 fixes the following issues: - Fix cve-2015-1606 (bsc#918089) * Invalid memory read using a garbled keyring * 0001-Gpg-prevent-an-invalid-memory-read-using-a-garbled-k.patch - Fix cve-2015-1607 (bsc#918090) * Memcpy with overlapping ranges * 0001-Use-inline-functions-to-convert-buffer-data-to-scala.patch
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152170-1/, https://bugzilla.suse.com/918089, https://bugzilla.suse.com/918090, https://www.suse.com/security/cve/CVE-2015-1606, https://www.suse.com/security/cve/CVE-2015-1607
Affected packages
Package
Name: gpg2
Purl: pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
