Gentoo Security Advisory GLSA 200312-05 (GnuPG)

The remote host is missing updates announced in advisory GLSA 200312-05.
All users who have created ElGamal signing keys should immediately revoke them. In addition, all Gentoo Linux machines with gnupg installed should be updated to use gnupg-1.2.3-r5 or higher: # emerge sync # emerge -pv '>=app-crypt/gnupg-1.2.3-r5' # emerge '>=app-crypt/gnupg-1.2.3-r5' # emerge clean
A bug in GnuPG allows ElGamal signing keys to be compromised, and a format string bug in the gpgkeys_hkp utility may allow arbitrary code execution.