Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-30258

Опубликовано: 19 мар. 2025
Источник: redhat
CVSS3: 2.7

Описание

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gnupg2Fix deferred
Red Hat Enterprise Linux 6gnupg2Out of support scope
Red Hat Enterprise Linux 7gnupg2Out of support scope
Red Hat Enterprise Linux 8gnupg2Out of support scope
Red Hat Enterprise Linux 9gnupg2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-754
https://bugzilla.redhat.com/show_bug.cgi?id=2353427gnupg: verification DoS due to a malicious subkey in the keyring

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
ubuntu
6 месяцев назад

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

CVSS3: 2.7
nvd
6 месяцев назад

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

CVSS3: 2.7
debian
6 месяцев назад

In GnuPG before 2.5.5, if a user chooses to import a certificate with ...

suse-cvrf
2 месяца назад

Recommended update for gpg2

CVSS3: 2.7
github
6 месяцев назад

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

2.7 Low

CVSS3