PT-2022-17010 · Php · Crypt Gpg

·

CVE-2022-24953

·

Published

2022-02-17

·

Updated

2023-08-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Crypt GPG extension for PHP versions prior to 1.6.7
Description The issue concerns the Crypt GPG extension for PHP, where it fails to prevent additional options in GPG calls. This poses a risk for certain environments and GPG versions.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue.

Exploit

Fix

RCE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24953
GHSA-59X4-67MH-PX54

Affected Products

Crypt Gpg