Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9234

Опубликовано: 19 мар. 2018
Источник: redhat
CVSS3: 2.2
EPSS Низкий

Описание

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnupgWill not fix
Red Hat Enterprise Linux 5gnupg2Will not fix
Red Hat Enterprise Linux 6gnupg2Fix deferred
Red Hat Enterprise Linux 7gnupg2Fix deferred
Red Hat Enterprise Linux 8gnupgNot affected
Red Hat Enterprise Linux 8gnupg2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-325
https://bugzilla.redhat.com/show_bug.cgi?id=1563930GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys

EPSS

Процентиль: 38%
0.0017
Низкий

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 7.5
nvd
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 7.5
debian
почти 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key ce ...

suse-cvrf
больше 2 лет назад

Security update for gpg2

CVSS3: 7.5
github
больше 3 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

EPSS

Процентиль: 38%
0.0017
Низкий

2.2 Low

CVSS3