USN-3733-1: GnuPG vulnerability


#1

The USN-3733-1: GnuPG vulnerability is fixed automatically and installed on SecureDrop production instances. I received the following OSSEC alert.

OSSEC HIDS Notification.
2018 Aug 07 04:14:41

Received From: mon->syscheck
Rule: 551 fired (level 7) -> "Integrity checksum changed again (2nd time)."
Portion of the log(s):

Integrity checksum changed for: '/usr/bin/gpg'
Old md5sum was: '94defe403a3eb9805cd72c79fd5937f5'
New md5sum is : '25e4d41e8a88a656bd61d87c6a2b0b18'
Old sha1sum was: '32c959bb834824e5d64185244f297348fd52e65f'
New sha1sum is : 'c6d9268ba09ba37ec6742f7836be849f5e80357f'


OSSEC HIDS Notification.
2018 Aug 07 04:14:39

Received From: mon->syscheck
Rule: 551 fired (level 7) -> "Integrity checksum changed again (2nd time)."
Portion of the log(s):

Integrity checksum changed for: '/usr/bin/gpgv'
Old md5sum was: '3378f62e61f7cfe43dab4091cf3b1f25'
New md5sum is : 'e189ba6ed164036eced0266747b30fee'
Old sha1sum was: '2461c52f37fe84fe6aec18fbb9f0b5239a57b504'
New sha1sum is : 'd475dd75c0a6725f1e1644d080eacbac2915e4fc'



 --END OF NOTIFICATION


OSSEC HIDS Notification.
2018 Aug 07 04:14:41

Received From: mon->syscheck
Rule: 551 fired (level 7) -> "Integrity checksum changed again (2nd time)."
Portion of the log(s):

Integrity checksum changed for: '/usr/bin/gpgsplit'
Old md5sum was: 'e2f144e7a901ac8a60e54c3791180121'
New md5sum is : 'a01387b0d682ff500b7dcc8391747f54'
Old sha1sum was: '02887b32d195dd87b48c929f10c450027b4b49d8'
New sha1sum is : '2b25afe9ee822d140d231e23484a01579c3414d3'



 --END OF NOTIFICATION