Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-34903

Опубликовано: 30 июн. 2022
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

A vulnerability was found in GnuPG. This issue occurs due to an escape detection loop at the write_status_text_and_buffer() function in g10/cpr.c. This flaw allows a malicious actor to bypass access control.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnupg2Out of support scope
Red Hat Enterprise Linux 6gpgmeNot affected
Red Hat Enterprise Linux 7gnupg2Out of support scope
Red Hat Enterprise Linux 7gpgmeNot affected
Red Hat Enterprise Linux 8gpgmeNot affected
Red Hat Enterprise Linux 9gpgmeNot affected
Red Hat Enterprise Linux 8gnupg2FixedRHSA-2022:646313.09.2022
Red Hat Enterprise Linux 9gnupg2FixedRHSA-2022:660220.09.2022
Red Hat Enterprise Linux 9gnupg2FixedRHSA-2022:660220.09.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2102868gpg: Signature spoofing via status line injection

EPSS

Процентиль: 77%
0.0112
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 6.5
nvd
почти 3 года назад

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 6.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 3 года назад

GnuPG through 2.3.6, in unusual situations where an attacker possesses ...

suse-cvrf
почти 3 года назад

Security update for gpg2

EPSS

Процентиль: 77%
0.0112
Низкий

5.9 Medium

CVSS3