CVE-2005-2023: Critical severity SUSE SuSE Linux vulnerability
Published Jun 17, 2005
·Updated
The sendpinentryenvironment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.
Affected Software
1 affected component
SUSE SuSE Linux=9.3
Remediation
Event History
Jun 17, 2005
CVE Published
04:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2023?
CVE-2005-2023 is classified as a security vulnerability that can impact S/MIME signing operations.
2
How do I fix CVE-2005-2023?
To fix CVE-2005-2023, update to a version of GPG that properly handles the options in the send_pinentry_environment function.
3
Which software is affected by CVE-2005-2023?
CVE-2005-2023 affects GPG2 on SUSE Linux version 9.3.
4
What type of issues does CVE-2005-2023 cause?
CVE-2005-2023 can cause pinentry to not be found, resulting in the failure of S/MIME signing.
5
Is there a workaround for CVE-2005-2023?
There may not be a reliable workaround for CVE-2005-2023, and the best course of action is to apply the recommended updates.