security flaw
Published Mar 13, 2006
5.0
MEDIUMCVSS 2.0
EPSS 2.43%
Description
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
Affected products
No data.
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.3b
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.2
- 1.2.1
- 1.2.2
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.3.3
- 1.3.4
- 1.4
- 1.4.1
- 1.4.2
- 1.4.2.1
No data.
Red Hat Enterprise Linux 3
gnupg-0:1.2.1-15
Fixed · RHSA-2006:0266
Red Hat Enterprise Linux 4
gnupg-0:1.2.6-3
Fixed · RHSA-2006:0266
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | gnupg-0:1.2.1-15 | Fixed | RHSA-2006:0266 |
| Red Hat Enterprise Linux 4 | gnupg-0:1.2.6-3 | Fixed | RHSA-2006:0266 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.43% (0.02430) | 83.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.37% (0.02373) | 81.59th | v5 (v2026.06.15) |
| Mar 30, 2025 | 4.48% (0.04481) | 88.06th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.29% (0.10294) | 88.53th | v4 (v2025.03.14) |
| Mar 19, 2025 | 4.48% (0.04481) | 87.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.92% (0.02921) | 85.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.60% (0.00600) | 79.18th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.60% (0.00600) | 77.78th | v3 (v2023.03.01) |
| May 9, 2023 | 0.60% (0.00600) | 75.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.62% (0.00620) | 75.55th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
No CWE recorded.
References (35)
- ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U vendor-advisoryx_refsource_SGI
- http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/19173 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19197 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19203 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19231 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19232 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19234 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19244 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19249 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19287 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19532 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/450 third-party-advisoryx_refsource_SREASON
- http://securityreason.com/securityalert/568 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015749 vdb-entryx_refsource_SECTRACKPatch
- http://www.debian.org/security/2006/dsa-993 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml vendor-advisoryx_refsource_GENTOOPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:055 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/23790 vdb-entryx_refsource_OSVDBPatch
- http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/support/errata/RHSA-2006-0266.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/427324/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/433931/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/17058 vdb-entryx_refsource_BIDPatch
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477 vendor-advisoryx_refsource_SLACKWARE
- http://www.trustix.org/errata/2006/0014 vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/0915 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-0049 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617870 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25184 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-0049
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/264-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-0049
Change history (0)
No recorded changes yet.