CVE-2019-14855
20.03.2020, 16:15
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnupg | gnupg | 𝑥 < 2.2.18 |
| canonical | ubuntu_linux | 18.04 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnupg1 |
| ||||||||||||||||
| gnupg2 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnupg |
| ||||||||||||||||||||||||||||
| gnupg1 |
| ||||||||||||||||||||||||||||
| gnupg2 |
|
Common Weakness Enumeration
References