Title : GnuPG "gpgv" Signature Verification Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-0610 CVE ID : CVE-2006-0455
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-02-15
Technical Description
A vulnerability has been identified in GnuPG, which could be exploited by attackers to bypass security restrictions and procedures. This flaw is due to an error in the "gpgv" tool and the "gpg --verify" command, that when used in certain unattended operation modes (e.g. by scripts and email programs), do not properly verify a detached signature containing multiple "0xCA" charaters, which could cause modified versions of signature protected files to bypass the signature verification process without being detected.