Vulnerabilities
Vulnerable Software
Gnupg:  >> Gnupg  >> 2.2.17  Security Vulnerabilities
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
CVSS Score
6.5
EPSS Score
0.012
Published
2022-07-01
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
CVSS Score
5.3
EPSS Score
0.001
Published
2020-03-20


Contact Us

Shodan ® - All rights reserved