UBUNTU-CVE-2019-13050
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-13050
UBUNTU-CVE-2019-13050
Summary:
Details: Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
References: https://ubuntu.com/security/CVE-2019-13050, https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f, https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html, https://tech.michaelaltfield.net/2019/07/14/mitigating-poisoned-pgp-certificates/, https://ubuntu.com/security/notices/USN-5431-1, https://www.cve.org/CVERecord?id=CVE-2019-13050
Affected packages
Package
Name: gnupg
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
