GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gpgme1.0Upgrade gnupg2 | Jul 30, 2024 | Mar 6, 2007 |
| Oracle_linux | — | Upgrade gnupg | Oct 16, 2024 | Mar 6, 2007 |
| Suse | — | Upgrade gpgUpgrade suse-release | Feb 17, 2015 | Mar 6, 2007 |
| Ubuntu | — | Upgrade libgpgme11Upgrade gnupg2Upgrade gnupg | Nov 8, 2024 | Mar 6, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub