Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24953

Опубликовано: 17 фев. 2022
Источник: debian

Описание

The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-crypt-gpgfixed1.6.7-1package
php-crypt-gpgfixed1.6.4-2+deb11u1bullseyepackage

Примечания

  • https://github.com/pear/Crypt_GPG/commit/74c8f989cefbe0887274b461dc56197e121bfd04 (v1.6.7)

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

CVSS3: 5.3
nvd
почти 4 года назад

The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

CVSS3: 5.3
github
почти 4 года назад

Crypt_GPG does not prevent additional options in GPG calls