Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7774-m57j-3qmq

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

EPSS

Процентиль: 76%
0.0096
Низкий

Связанные уязвимости

redhat
больше 24 лет назад

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

nvd
больше 24 лет назад

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

EPSS

Процентиль: 76%
0.0096
Низкий