PT-2018-18919 · Gnu+2 · Gnupg+2

Lance Vick

·

Published

2018-04-03

·

Updated

2024-06-15

·

CVE-2018-9234

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GnuPG versions 2.2.4 through 2.2.5
Description The issue concerns a configuration where key certification does not require an offline master Certify key. This results in apparently valid certifications that can occur with access to only a signing subkey.
Recommendations For GnuPG versions 2.2.4 and 2.2.5, consider configuring the system to enforce the use of an offline master Certify key for key certification to prevent apparently valid certifications from occurring with access to only a signing subkey. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9234
MGASA-2018-0254
OPENSUSE-SU-2024:10815-1
SUSE-SU-2023:3857-1
SUSE-SU-2023_3857-1
USN-3675-1

Affected Products

Gnupg
Suse
Ubuntu