UBUNTU-CVE-2022-34903
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-34903
UBUNTU-CVE-2022-34903
Summary:
Details: GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
References: https://ubuntu.com/security/CVE-2022-34903, https://dev.gnupg.org/T6027, https://www.openwall.com/lists/oss-security/2022/06/30/1, https://bugs.debian.org/1014157, http://www.openwall.com/lists/oss-security/2022/07/02/1, https://ubuntu.com/security/notices/USN-5503-1, https://ubuntu.com/security/notices/USN-5503-2, https://www.cve.org/CVERecord?id=CVE-2022-34903
Affected packages
Package
Name: gnupg
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
