CVE-2022-34903
01.07.2022, 22:15
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
Vendor | Product | Version |
---|---|---|
gnupg | gnupg | 𝑥 ≤ 2.3.6 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
netapp | active_iq_unified_manager | - |
netapp | ontap_select_deploy_administration_utility | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gnupg |
| ||||||||||||
gnupg2 |
|
References