PT-2018-18919 · Gnu+2 · Gnupg+2

Lance Vick

·

Publicado

2018-04-03

·

Atualizado

2024-06-15

·

CVE-2018-9234

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GnuPG versions 2.2.4 through 2.2.5
Description The issue concerns a configuration where key certification does not require an offline master Certify key. This results in apparently valid certifications that can occur with access to only a signing subkey.
Recommendations For GnuPG versions 2.2.4 and 2.2.5, consider configuring the system to enforce the use of an offline master Certify key for key certification to prevent apparently valid certifications from occurring with access to only a signing subkey. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9234
MGASA-2018-0254
OPENSUSE-SU-2024:10815-1
SUSE-SU-2023:3857-1
SUSE-SU-2023_3857-1
USN-3675-1

Produtos afetados

Gnupg
Suse
Ubuntu