[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4222-1 gnupg2 -- gnupg2

ID: oval:org.secpod.oval:def:603420Date: (C)2018-06-11   (M)2023-12-20
Class: PATCHFamily: unix




Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email. Details can be found in the upstream advisory at https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html

Platform:
Debian 8.x
Debian 9.x
Product:
dirmngr
gnupg
scdaemon
gpgsm
gpgv
Reference:
DSA-4222-1
CVE-2018-12020
CVE    1
CVE-2018-12020
CPE    6
cpe:/o:debian:debian_linux:9.0
cpe:/a:gnupg:gnupg:2.0.0
cpe:/o:debian:debian_linux:8.x
cpe:/a:gnupg:gnupg
...

© SecPod Technologies