Description: A security issue has been reported in GnuPG, which potentially can be exploited by malicious people to bypass certain security restrictions.
The security issue is caused due to "gpgv" exiting with a return code of 0 even if the detached signature file did not carry any signature. This may result in certain scripts that use "gpgv" to conclude that the signature is correctly verified.
Successful exploitation requires that "gpgv" or "gpg --verify" is used from a script that determines whether the file signature is correctly verified based on the return code.
The security issue has been reported in versions prior to 1.4.2.1.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.