Tavis Ormandy discovered a flaw in gnupg’s signature verification. In some cases, certain invalid signature formats could cause gpg to report a ‘good signature’ result for auxiliary unsigned data which was prepended or appended to the checked message part.
The problem can be corrected by updating your system to the following package versions:
4 April 2006
A security issue affects these releases of Ubuntu and its derivatives:
Tavis Ormandy discovered a flaw in gnupg’s signature verification. In some cases, certain invalid signature formats could cause gpg to report a ‘good signature’ result for auxiliary unsigned data which was prepended or appended to the checked message part.
The problem can be corrected by updating your system to the following package versions:
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.