CVE-2019-14855
20.03.2020, 16:15
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.Enginsight
Vendor | Product | Version |
---|---|---|
gnupg | gnupg | 𝑥 < 2.2.18 |
canonical | ubuntu_linux | 18.04 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gnupg1 |
| ||||||||||||||||
gnupg2 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gnupg |
| ||||||||||||||||||||||||||||
gnupg1 |
| ||||||||||||||||||||||||||||
gnupg2 |
|
Common Weakness Enumeration
References