PT-2019-12434 · Signing Party+1 · Signing-Party+1

Sec

+1

·

Publicado

2019-04-30

·

Atualizado

2024-06-15

·

CVE-2019-11627

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions signing-party versions 1.1.x through 2.9
Description The issue concerns an unsafe shell call in the gpg-key2ps component, which enables shell injection. This can be exploited via a User ID.
Recommendations For versions 1.1.x through 2.9, consider disabling the gpg-key2ps component until a patch is available. Restrict access to the User ID field to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11627
DLA-1773-1
MGASA-2019-0386
OPENSUSE-SU-2019:1388-1
OPENSUSE-SU-2019_1388-1
OPENSUSE-SU-2024:11383-1

Produtos afetados

Suse
Signing-Party