GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade gnupg2Upgrade gnupgUpgrade gnupg2 | May 31, 2018 | Apr 3, 2018 |
| Debian | — | Upgrade gnupg2 | Jul 30, 2024 | Apr 4, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gnupg2 | Dec 4, 2019 | Apr 4, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade gnupg2 | Dec 18, 2019 | Apr 4, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gnupg2 | Mar 24, 2021 | Apr 4, 2018 |
| Oracle Solaris | — | Upgrade security/pinentry to version 1.1.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/security/gpgme to version 1.11.1-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/security/libgpg-error to version 1.31-11.4.9.0.1.1.0 on Solaris 11.4Upgrade security/pinentry-gtk to version 1.1.0-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/security/libksba to version 1.3.5-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/pth to version 2.0.7-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/gmime to version 2.6.23-11.4.9.0.1.1.0 on Solaris 11.4Upgrade crypto/gnupg to version 2.2.8-11.4.9.0.1.1.0 on Solaris 11.4Upgrade system/library/security/libgcrypt to version 1.8.3-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/security/libassuan to version 2.5.1-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/npth to version 1.5-11.4.9.0.1.1.0 on Solaris 11.4 | May 30, 2019 | Apr 4, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 4, 2018 |
| Suse | — | Upgrade gpg2Upgrade gpg2-langUpgrade dirmngr | May 19, 2018 | Apr 3, 2018 |
| Ubuntu | — | Upgrade gpgUpgrade gnupg | Jun 13, 2018 | Apr 3, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub