PT-2022-17010 · Php · Crypt Gpg

Thomas-Chauchefoin-Sonarsource

·

Published

2022-02-17

·

Updated

2023-08-08

·

CVE-2022-24953

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Crypt GPG extension for PHP versions prior to 1.6.7
Description The issue concerns the Crypt GPG extension for PHP, where it fails to prevent additional options in GPG calls. This poses a risk for certain environments and GPG versions.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue.

Fix

Argument Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-24953
GHSA-59X4-67MH-PX54

Affected Products

Crypt Gpg