Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sec

#23499of 53,608
10Total CVSS
Vulnerabilities · 1
PT-2019-12434
10
2019-04-30
Signing Party · Signing-Party · CVE-2019-11627
**Name of the Vulnerable Software and Affected Versions** signing-party versions 1.1.x through 2.9 **Description** The issue concerns an unsafe shell call in the gpg-key2ps component, which enables shell injection. This can be exploited via a User ID. **Recommendations** For versions 1.1.x through 2.9, consider disabling the gpg-key2ps component until a patch is available. Restrict access to the User ID field to minimize the risk of exploitation.