Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9234

Опубликовано: 04 апр. 2018
Источник: debian

Описание

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnupg2fixed2.2.7-1package
gnupg2no-dsastretchpackage
gnupg2no-dsajessiepackage
gnupg2no-dsawheezypackage

Примечания

  • https://dev.gnupg.org/T3844

  • https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=a17d2d1f690ebe5d005b4589a5fe378b6487c657

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 2.2
redhat
больше 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 7.5
nvd
больше 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

suse-cvrf
почти 3 года назад

Security update for gpg2

CVSS3: 7.5
github
больше 4 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.