ZeroHour

CVE-2022-34903

PoC ×2
CVSS 3.1
6.5 medium
EPSS
3%p85
Published
()
Modified
Description

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

Vendors
gnupgfedoraprojectdebiannetapp
Products
gnupg, fedora, debian linux, active iq unified manager, ontap select deploy administration utility
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.