Gentoo: gnupg key validation bug
Summary
GENTOO LINUX SECURITY ANNOUNCEMENT 200305-04
- From advisory:
"As part of the development of GnuPG 1.2.2, a bug was discovered in the key validation code. This bug causes keys with more than one user ID to give all user IDs on the key the amount of validity given to the most-valid key."
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105215110111174&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running app-crypt/gnupg upgrade to gnupg-1.2.2 as follows:
emerge sync emerge gnupg emerge clean
aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background