Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9234

Опубликовано: 04 апр. 2018
Источник: debian
EPSS Низкий

Описание

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnupg2fixed2.2.7-1package
gnupg2no-dsastretchpackage
gnupg2no-dsajessiepackage
gnupg2no-dsawheezypackage

Примечания

  • https://dev.gnupg.org/T3844

  • https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=a17d2d1f690ebe5d005b4589a5fe378b6487c657

EPSS

Процентиль: 38%
0.0017
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 2.2
redhat
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 7.5
nvd
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

suse-cvrf
больше 2 лет назад

Security update for gpg2

CVSS3: 7.5
github
больше 3 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

EPSS

Процентиль: 38%
0.0017
Низкий