CVE-2006-0049: Medium severity GNU Privacy Guard vulnerability
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0049?
CVE-2006-0049 has a moderate severity rating due to its potential impact on the integrity of signatures in GnuPG.
How do I fix CVE-2006-0049?
To fix CVE-2006-0049, you should upgrade GnuPG to version 1.4.2.2 or later, which addresses this vulnerability.
Which versions of GnuPG are affected by CVE-2006-0049?
GnuPG versions prior to 1.4.2.2, including 1.4.2, 1.4.1, and earlier, are affected by CVE-2006-0049.
What type of attack is possible with CVE-2006-0049?
CVE-2006-0049 allows attackers to inject unsigned data by exploiting improper verification of non-detached signatures.
Is CVE-2006-0049 a known vulnerability in GnuPG?
Yes, CVE-2006-0049 is a recognized vulnerability in GnuPG that was published in 2006 affecting earlier versions.